On March 6, 2026, the North Central HIDTA appeared on the leak site of the DragonForce ransomware group in a listing claiming internal files were exfiltrated during a ransomware attack. The organization, which coordinates drug-trafficking investigations across Minnesota, Wisconsin, and tribal lands, has not yet confirmed the number of individuals whose information may have been exposed.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch North Central HIDTA
Get alerted the next time North Central HIDTA files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about North Central HIDTA’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting indicates that DragonForce posted a notice claiming successful exfiltration of internal documents from North Central HIDTA. The breach involved ransomware deployment followed by data theft, a pattern consistent with the group’s operations. No exact victim count or detailed list of exposed records has been released by the agency or the attackers. The primary source remains the DragonForce leak site, indexed by ransomware.live at the onion address provided below.
Why This Matters for You and Your Family
When a law-enforcement intelligence hub is breached, the ripple effects reach far beyond government offices. North Central HIDTA maintains records on investigations, informants, task-force participants, and community partners. If your name, address, phone number, or email appears in any of those files, that information may now be in the hands of criminals. Personal details stolen from such networks are frequently resold on dark-web markets and used to launch follow-on attacks against ordinary families. Even if you have never been the direct target of a drug investigation, shared databases mean one breach can expose information about witnesses, local officers, support staff, and their households.
The Doxxing and Identity-Chain Implications
Ransomware groups rarely stop at the first dataset. Once internal files leave an organization, attackers or buyers map connections between work emails, personal accounts, family addresses, and online handles. A single leaked government email can link to your spouse’s social-media profile, your children’s school records, or gaming usernames. These identity chains allow criminals to impersonate family members, file fraudulent claims, or harass you directly. Credential leaks of this nature frequently cascade into account takeovers, especially for gaming accounts that reuse the same passwords or security questions. Children’s profiles are particularly vulnerable because parents often link them to household addresses or recovery emails that also appear in the stolen files.