MCMINNVILLE Ore. (KPTV) – The City of McMinnville knew something was wrong with its computer network in mid-July. It didn’t tell the public until mid-September. And it didn’t send formal notice to the people whose Social Security numbers and driver’s license numbers may have been stolen until September 29 — a date the city’s own account suggests came more than a month past the deadline Oregon law sets for this kind of thing.
The city isn’t disputing any of that timeline. It just won’t explain it.
“At this time, the city does not have any additional comment beyond the information provided in the notice,” City Manager Adam Garvin wrote in response to written questions this week, pointing back to the same notice that started the questions in the first place.
Here’s what’s known.
McMinnville says it first noticed unusual activity on its network on or about July 15. An investigation that followed found that someone had gotten into the system and copied files — some containing names, Social Security numbers and driver’s license numbers — sometime between June 1 and July 18, according to a notice the city sent affected individuals in late September.
A ransomware group called RansomHouse claimed responsibility, posting McMinnville on its dark web site. FOX 12 independently visited that site and confirmed the city’s listing. Without opening or downloading any of the files themselves, we could also see file titles consistent with police records, city personnel files and internal investigations — a detail a local cybersecurity expert, who says he separately reviewed the same leak, backs up.
“This is all the city’s dirty laundry out there,” said Chuck Dornan, who runs the McMinnville-based cybersecurity firm Alexonet. “HR records, internal affairs investigations, payroll information… I would say it’s about as serious as it comes, honestly, from what I’ve seen.”
Dornan’s firm does similar work to VC3, the company McMinnville ultimately hired to manage its IT and cybersecurity going forward. The city had already selected VC3 before Dornan spoke with FOX 12, and he is not seeking that contract — he’s serving solely as an outside cybersecurity expert for this story.
The math the city won’t talk about
Under Oregon’s Consumer Information Protection Act, state law requires that government agencies and businesses give notice of a data breach “in the most expeditious manner possible, without unreasonable delay,” and no later than 45 days after discovering it, according to ORS 646A.604. Count 45 days from July 15, and you land around August 29. McMinnville’s formal notice went out a month after that.
Dornan says there’s really only one legal way around that deadline.
“The only way they can extend that — and this is from me reading and talking with people in the know — is law enforcement, if it impedes their investigation, can extend that window,” he said. “That is the only exception.”
So FOX 12 asked the city directly: Why did formal notice to affected individuals not go out until September 29, a month past that window?
The city didn’t answer. Nor did it answer a second, more pointed question: Did officials already know Social Security numbers and driver’s license numbers had been exposed on September 22 — the same night the City Council voted to approve a $1.28 million cybersecurity contract with an outside firm, VC3?
The Oregon Department of Justice may have its own questions. According to the Oregon DOJ, the state only recently received notice of the breach from McMinnville and is now reviewing the case, including the timeline the city has given for when it knew what. It’s not clear when that review might wrap up, or whether it could lead to any formal action.
Is there a different reading of the clock?
The city hasn’t offered an explanation for the gap, but its own notice leaves room for one argument it hasn’t yet made out loud: that the 45-day clock didn’t start on July 15 at all.
Look closely at the wording. The city says it became aware of “unusual activity” on July 15 — not, at that point, a confirmed breach of personal information. It says the investigation “revealed” that data “may have been accessed and copied” sometime before July 18. And it says the review to determine “what sensitive and/or personal information was impacted and to whom it related” wasn’t even “in-part” finished until September 22.
Read that way, the city could argue the clock didn’t start until it actually confirmed whose personal information was involved — sometime in late September — which would put its September 29 notice only about a week past discovery, not a month.
FOX 12 asked Garvin’s office directly whether that is, in fact, the city’s position: Does the city consider July 15 the date of discovery under Oregon law, or does it consider the clock to have started later, once the review identified specific individuals’ data? The city has not answered.
Dornan doesn’t buy the later start date.
“The first thing that should have been done is the city should have been a little more transparent and reached out to these individuals,” he said, arguing the obligation to act attaches once an organization knows something serious has happened — not once every detail is nailed down. Oregon’s statute requires notice “without unreasonable delay,” language regulators and courts have generally read as foreclosing exactly this kind of multi-month internal review before the clock starts.
Whether that reading holds up may now rest with the Oregon Department of Justice, which — as noted above — is reviewing the city’s timeline without yet saying which interpretation it’s applying.
Watch the footage from that council meeting and you won’t hear anyone say the word “breach.” Council members talked about “recent headlines” and the state racking up $775 million in cyber losses over five years. The city’s information systems director acknowledged the city’s IT staffing hadn’t changed since 2003, and that McMinnville had never had round-the-clock threat monitoring before. Nobody in the room that night said, out loud, that any of this was because of what had already happened to their own network.
RansomHouse isn’t a group federal investigators are unfamiliar with. A joint advisory from the FBI, the Cybersecurity and Infrastructure Security Agency and the Department of Defense Cyber Crime Center names RansomHouse as one of several ransomware operations that has worked with Iran-linked hackers to break into U.S. networks — including, in the past, municipal governments, alongside schools, hospitals and financial institutions. The advisory doesn’t tie this specific attack to Iran, and there’s no evidence it was involved here. But it’s a reminder that the group putting McMinnville’s files up for anyone to find isn’t some fringe operation — it has a track record, and federal agencies have been watching it for years.
Dornan says the group’s business model has shifted from the earlier days of ransomware, when hackers simply locked up a victim’s files and demanded payment to unlock them.
“It’s twofold. They double-dip,” he said. “They get into your network and they exfiltrate all the data… And then they encrypt all your data. They hold it hostage… Then, if you ignore that or you pay that ransom, then what they do is say, OK, well, now we’ve got all this information. What are you going to do to keep us from [releasing] this?”
And increasingly, he says, you don’t need much technical skill to pull it off.
“They’ll send explicit instructions on how to do this. And if you [need help], they’ve got a help desk that you can contact,” Dornan said. “No longer is it just these guys sitting in the basement. It could be 15, 16-year-old kids that’s doing this stuff. In all ages. It’s just — the biggest motivator for a lot of this is money.”
McMinnville says it’s mailing letters to people whose information was confirmed to be part of the breach, and has set up a dedicated phone line for questions. People who did business with the city — paid a utility bill, got a permit, interacted with police or the municipal court — may want to watch for that letter, or call the city directly if they’re worried and haven’t heard anything yet.
Dornan’s advice is the same thing security experts tell people after just about every breach like this, because it still works: freeze or monitor your credit, sign up for credit monitoring if it’s offered, and stop reusing the same password everywhere.
“You’re going to have to monitor your credit,” he said. “Sign up with credit protection… use unique passwords for every site you go to.”
FOX 12 has filed public records requests with the city seeking records tied to the VC3 contract and any internal correspondence about when officials knew what. The McMinnville Police Department has not responded to questions about whether police records were part of what was exposed.
Garvin’s office says the investigation is ongoing and that “additional information will be shared when appropriate.” He has not said when that might be.
Copyright 2026 KPTV-KPDX. All rights reserved.
