LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Ohio Lottery Listed by dragonforce Ransomware Group

HIGH severity claimedUnverified claimHow we verify

Ohio Lottery Listed by dragonforce Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·December 21, 2023
Ohio Lottery Listed by dragonforce Ransomware Group

Reported December 21, 2023.

HIGH
Severity
December 21, 2023
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The Ohio Lottery Listed by dragonforce Ransomware Group (reported December 21, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
HIGH severity claimedUnverified claim
Exposes government-ID data.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

On December 21, 2023, the Ohio Lottery was listed by the ransomware group dragonforce, which claimed responsibility for a ransomware attack involving the exfiltration of internal files. Public detail on the incident remains limited: the number of people affected is unknown, and independent confirmation of the full scope has not been established beyond the group's own statements.

The listing matters because lottery operators routinely handle sensitive personal and financial information belonging to players and staff. Any confirmed exposure of such data can create lasting risks of identity misuse and fraud, even when exact figures and timelines stay incomplete.

What happened

According to available reporting, the Ohio Lottery appeared on dragonforce's leak site on December 21, 2023. The group described the event as a ransomware attack in which internal files were allegedly exfiltrated. No public technical details have been released about the initial access method, the duration of any intrusion, or whether systems were encrypted in addition to data theft. The scale of impact on individuals is listed as unknown.

Dragonforce's own summary asserted that more than 3,000,000 entries were involved and referenced first names, last names, email addresses, physical addresses, winning amounts, and Social Security numbers plus dates of birth for employees and players. These assertions originate with the group and have not been independently verified in the public record. Beyond the leak-site listing and the claimed file exfiltration, further operational specifics remain undisclosed.

The group behind it: dragonforce

Dragonforce is a known ransomware operation that follows the double-extortion model common among contemporary groups: data is stolen before systems are encrypted, and victims are pressured with the threat of public release if a ransom is not paid. The group maintains a leak site where it posts victim names and, in some cases, sample data or full archives to increase leverage. Like other ransomware actors, it has historically targeted a range of sectors rather than specializing in a single industry.

Public reporting on dragonforce has noted its use of standard ransomware tactics, including initial access through compromised credentials or vulnerabilities, lateral movement inside networks, and the packaging of stolen files for later publication. In this instance, the group's listing of the Ohio Lottery constitutes a claim of responsibility and data theft; it does not by itself constitute confirmed proof of every detail asserted in the accompanying summary. No additional statements from the group specific to this victim, beyond the listing and the quoted claims about file contents, appear in the available facts.

About Ohio Lottery

The Ohio Lottery is the state-operated lottery of Ohio, responsible for running games of chance, selling tickets through retailers, managing prize payouts, and overseeing related player and retailer accounts. Organizations of this type typically maintain databases of player registrations, winner records, payment details, and internal employee information in order to comply with tax reporting, anti-fraud rules, and prize distribution requirements.

A breach affecting a state lottery is consequential because the data holdings often combine ordinary contact information with higher-sensitivity identifiers and financial outcome records. Players may have supplied personal details when claiming prizes or creating accounts; employees' records are held for payroll and administrative purposes. Compromise of either category can expose individuals to targeted scams or identity theft and can undermine public confidence in the integrity of lottery operations.

What data was at risk

The facts state that internal files were exfiltrated in a ransomware attack. Dragonforce claimed the material included more than 3,000,000 entries containing first names, last names, email addresses, physical addresses, winning amounts, and Social Security numbers together with dates of birth for both employees and players. These data-type assertions are the group's claims and are not independently confirmed in the public record.

Exact contents therefore remain unconfirmed. Lottery operators commonly hold player contact data, prize and tax-related records, and employee personnel files; whether every category the group named was in fact present, complete, or accurately described cannot be established from the available information alone. The number of people affected is unknown.

The real-world impact

If the claimed data types were exposed, affected individuals could face elevated risks of identity theft, tax-related fraud, and highly personalized phishing. Names combined with addresses, dates of birth, and Social Security numbers are sufficient for many forms of account takeover or fraudulent credit applications. Knowledge of winning amounts could also be used to craft convincing social-engineering attempts aimed at prize claimants.

For the Ohio Lottery itself, the incident raises operational and reputational concerns: the need to investigate the intrusion, notify regulators and potentially affected parties, and harden systems against further abuse. Because the count of affected people is unknown and independent verification of the full data set is lacking, the precise breadth of harm cannot yet be quantified. Residual risk persists for anyone whose information may have been included, regardless of whether a ransom was paid or files were later published.

If your data was in this claimed breach

Monitor financial and credit accounts for unfamiliar activity and consider placing a fraud alert or credit freeze with the major credit bureaus. Be cautious of unsolicited calls, emails, or messages that reference lottery winnings, personal details, or urgent payment requests. If you are an employee or a player who has claimed prizes or maintained an account with the Ohio Lottery, review any official notifications the organization may issue and follow its guidance on password changes or additional verification steps.

You can also run a free exposure scan of your email address to check whether your information has already surfaced in known breach data sets. Remaining alert to unusual account behavior and keeping contact and authentication details current remain practical first steps while fuller details of this incident stay limited.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyOhio Lottery security record
88/100
DoxxScan™ · Low doxx risk
B 83Good record

1 reported incident on record.

See Ohio Lottery’s full breach history →

More recent breaches

North Central HIDTA Listed by dragonforce Ransomware GroupMarch 6, 2026City of La Vergne Listed by dragonforce Ransomware GroupOctober 17, 2025City of Keene, NH Listed by dragonforce Ransomware GroupJuly 7, 2025Strafford County NH Listed by dragonforce Ransomware GroupJune 16, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the Ohio Lottery Listed by dragonforce Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by dragonforce — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram