The City of Columbus, OH, sues security researcher David Leroy Ross, aka Connor Goodwolf, accusing him of sharing data stolen by a ransomware gang with media
Columbus’s suit places a researcher’s handling of ransomware-stolen material at the center of a dispute that has usually focused on the attackers and the breached organization. Earlier coverage showed how ransomware groups use threatened publication to pressure victims, including the threat to expose sensitive police files in Washington, D.C.
The case also sits beside a contested disclosure ecosystem: DDoSecrets previously published a large cache initially leaked by ransomware actors, while a researcher recently used deceptive personas to investigate LockBit. The key distinction here is not simply access to data, but what a third party may do after obtaining it.
First-order effects
David Leroy Ross, known as Connor Goodwolf, must defend against Columbus’s allegation that he shared ransomware-stolen data with media outlets; the city is using civil litigation to challenge that dissemination.
Media outlets and researchers handling breach material face a more visible permission and liability question when a victim organization contests onward sharing.
Second-order effects
Security researchers may reassess how they document provenance, minimize handling, and coordinate disclosure when ransomware data is involved, rather than treating public availability as a clear right to redistribute.
Victims of extortion attacks may view legal action against downstream distributors as another response alongside efforts to contain the original breach, potentially sharpening conflict with transparency-oriented publishers.
Third-order effects
If similar cases proliferate, the industry may develop clearer norms around the publication of ransomware-leaked datasets—separating research, reporting, and redistribution more explicitly.
The broader boundary will likely be shaped case by case: litigation can deter circulation of stolen data, but overly broad claims could also constrain independent breach research and public-interest reporting.
The trend: Ransomware’s data-theft phase is expanding the security debate from stopping attackers to defining the legal and ethical boundaries for researchers, publishers, and victims who encounter stolen data.
Using this as an opportunity to remind Cbus residents & nonresidents concerned w/ their personal info having gotten hacked & shared with on the dark web to sign up for the city's (not at all well advertised lol) monitoring & protection services by Nov 29: https://www.columbus.gov…
https://www.dispatch.com/... City goes after guy who informed public of the true massiveness of city's data loss of sensitive citizen information. Still unclear of he knows more than they do about what they did, since no city official is talking about what the details of what hap…
This is screwed up. A whistleblower showed the city of Columbus wasn't being honest about the extent of the data leak, and to prove it, he showed reporters how anybody could access all that data on the dark web, and now the city is going after him legally? https://www.dispatch.co…
I hope this decision gets reversed and soon. For @MayorGinther - the targeting of @cgoodwolf is not a good look. The data was/is already public and accessible to anyone that has a TOR browser. The data is already exposed and gone. Targeting security researchers for
BREAKING: Columbus seeks restraining order to block cybersecurity expert Connor Goodwolf from releasing data from hack Press conference is about to begin at 2:45 pm. https://www.wosu.org/...
City of Columbus has asked for restraining order stopping a local computer guru from telling the public what's really going on with data theft. https://www.dispatch.com/...
UPDATE: City Attorney Zach Klein told reporters today the city is seeking this restraining order on Connor Goodwolf to prevent him from disclosing more data from the dark web “This is personal, confidential information. This is investigatory records.” https://www.wosu.org/...
What's also screwed up is how little info Columbus “leaders” have given to us about any of it. Not a single public post from city council members, nothing (really) from the mayor except initial lies about the impact, but time to go after the one person actually sharing facts? 🤔
City of Columbus sues cybersecurity expert who exposed extent of data breach The cybersecurity expert, Connor Goodwolf, has spoken with 10TV and other media outlets in the last few weeks detailing what information is on the dark web. https://www.10tv.com/...
City of Columbus sues cybersecurity expert who exposed extent of data breach The cybersecurity expert, Connor Goodwolf, has spoken with 10TV and other media outlets in the last few weeks detailing what information is on the dark web. https://www.10tv.com/...