LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › City of Fort Smith Arkansas Listed by Interlock Ransomware Group

HIGH severityUnverified claimHow we verify

City of Fort Smith Arkansas Listed by Interlock Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·September 15, 2026
City of Fort Smith Arkansas Listed by Interlock Ransomware Group

Occurred August 2026 · publicly disclosed September 15, 2026.

HIGH
Severity
September 15, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The City of Fort Smith Arkansas was listed by the Interlock ransomware group on September 15, 2026, with the group claiming to hold data belonging to an undisclosed number of people. Individuals should check any official statements from the city and consider monitoring their accounts for unusual activity.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

On September 15, 2026, the ransomware group known as Interlock listed the City of Fort Smith, Arkansas, on its leak site. The listing is an unverified accusation from the group. As of writing, the city has not publicly confirmed that an incident occurred, that systems were accessed, or that any data left its control. Public detail beyond the existence of the listing is limited.

Listings of this kind matter because municipal governments hold records tied to residents, employees, and essential local services. Until independent confirmation exists, the responsible approach is to treat the post as a claim, understand what such claims usually imply, and take proportionate precautions if personal information could be involved.

What is being claimed

Interlock has listed the City of Fort Smith, Arkansas, on its leak site and presented the entry as evidence of a compromise involving confidential municipal material. According to the listing-related summary associated with the report, the group claims a large volume of data—described as over 5.6 TB—and refers to material connected to key local infrastructure, including references to public-safety-related environments such as police, fire, and emergency communications functions. Those descriptions come from the claimant, not from a confirmed inventory.

The number of people potentially affected is unknown. Exact data types are not disclosed in a verified form. Timing of any alleged intrusion, initial access method, dwell time, and whether any files were actually transferred are undisclosed in public reporting tied to this record. Nothing in the available facts establishes that the city’s systems were in fact breached or that the advertised volume or categories are accurate.

The group behind it: Interlock

Interlock is known publicly as a ransomware and extortion-oriented actor that pressures organizations by encrypting systems and by threatening to publish stolen data on a dedicated leak site. Like other groups in this category, it typically relies on double-extortion messaging: operational disruption paired with reputational and regulatory pressure from alleged data exposure. Public reporting on Interlock has generally described affiliate-style or service-like ransomware activity, negotiation pages, and staged releases meant to increase leverage when victims do not pay.

For this specific listing, only the group’s own claims about the City of Fort Smith are on record in the facts provided. No independent confirmation of those claims is included. Leak-site posts are marketing and coercion tools; they can exaggerate scale, recycle older material, misattribute data, or invent detail. The presence of a listing establishes that Interlock chose to name the city. It does not, by itself, establish what happened inside the city’s networks.

City of Fort Smith Arkansas and its sector

Fort Smith is a municipal government serving residents in western Arkansas. Cities in this role typically operate public safety, emergency communications, utilities coordination, permitting, finance, human resources, courts-related administration, and a range of resident-facing services. They routinely hold identity data, contact information, property and tax records, employee personnel files, vendor contracts, and operational documents needed to run day-to-day government.

A credible incident affecting a city government would be consequential because residents depend on continuity of services and because civic records can be reused for fraud, targeted scams, or harassment. At the same time, an unconfirmed leak-site entry does not prove service disruption or data loss. What the listing does establish is public naming by an extortion group. What it does not establish is the scope, accuracy, or even the reality of the alleged compromise.

What was likely exposed

Named data types in the factual record are not disclosed in a confirmed way. Interlock’s listing language claims a major release of confidential material and points to infrastructure- and public-safety-adjacent themes, including references to police, fire, and communications functions tied to emergency response. Those points remain the group’s assertions.

If files from a city government were ever taken, organizations in this sector typically hold some combination of the following categories. None of these should be read as a confirmed inventory for this case:

Exact contents, file counts, and whether any of the above were involved remain unconfirmed. Conditional risk assessment is appropriate; treating the attacker’s catalog as fact is not.

What's at stake

For residents and staff, the practical stakes—if personal or financial information were involved—include phishing and social-engineering attempts that reference local government services, account takeover attempts using reused passwords, tax- or benefit-related fraud, and misuse of addresses or phone numbers for scams. Public-safety-adjacent records, if genuine and exposed, could raise additional concerns about sensitive operational detail; that possibility is conditional on the listing being accurate, which is not established here.

For the city as an organization, an extortion listing can create public concern, distract staff, and invite follow-on fraud against people who trust municipal communications. Even when a claim is false or inflated, the naming alone can generate support burden and confusion. None of that proves negligence or confirms a successful theft; it reflects how leak-site pressure campaigns work.

What to do now

Treat this as an unconfirmed claim. The City of Fort Smith has not publicly confirmed the claim as of writing. If you have a relationship with the city as a resident, employee, or vendor, watch for unusual messages that urge urgent payments, credential entry, or transfer of funds, and verify any such contact through official channels you already trust—not through links in unexpected emails or texts.

Practical steps if your information might be involved: monitor financial and credit activity; use unique passwords and multi-factor authentication on email and financial accounts; be skeptical of messages that cite a “city breach” to demand action; and follow only official city notices if any are issued. Free exposure-scan tools can check whether an email address has already appeared in known breach datasets; a match does not prove connection to this listing, and a clean result does not rule out every risk, but it is a reasonable hygiene check.

Remain measured. A ransomware group’s leak-site post is a claim under pressure, not a verified breach report. Adjust personal security habits where the conditional risk warrants it, and wait for confirmed information before assuming specific records were taken.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyCity of Fort Smith Arkansas security record
84/100
DoxxScan™ · Low doxx risk
B- 76Above-average record

1 reported incident on record.

See City of Fort Smith Arkansas’s full breach history →
RelatedMore incidents at City of Fort Smith Arkansas

More recent breaches

Southeastern Oklahoma State University Listed by Interlock Ransomware GroupAugust 19, 2026Gardiner Family Chiropractic Listed by Interlock Ransomware GroupJuly 31, 2026Paragon Store Fixtures Listed by Interlock Ransomware GroupJuly 17, 2026District of Columbia Housing Authority Listed by Interlock Ransomware GroupJuly 16, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the City of Fort Smith Arkansas Listed by Interlock Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by interlock — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram