Shelbyville Police Department Listed by interlock Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Shelbyville Police Department was listed by the interlock ransomware group on November 05, 2025, with internal files reported to have been exfiltrated in the attack. An undisclosed number of people may have been affected; anyone with prior contact with the department should verify their information and monitor accounts for unusual activity.
On 5 November 2025 the Shelbyville Police Department was listed on a leak site operated by the interlock ransomware group. The group claims it carried out a ransomware attack that exfiltrated internal files and gained access to cameras, archived video, crime footage and related databases. The number of people whose information may be involved remains unknown, and public detail about the precise scale and method is limited. For residents, officers and anyone whose personal or case-related data sits in police systems, the practical stakes are immediate: sensitive records that could be misused for identity fraud, harassment or interference with ongoing investigations may now be in unauthorised hands.
Law-enforcement agencies hold some of the most intimate and consequential information communities generate. When that material is claimed to have left controlled systems, the risk is not abstract; it can affect personal safety, privacy and trust in local policing.
Inside the incident
Public reporting of the incident dates to 5 November 2025, when interlock listed the Shelbyville Police Department. According to the group’s own statement, a ransomware attack allowed it to exfiltrate internal files and obtain access to the department’s cameras, all data and databases containing archived videos and crime footage, as well as all available cameras and devices that record audio or video. The group characterises the volume as “a vast amount of confidential data.” No independent confirmation of these claims has been published, the number of people affected is listed as unknown, and technical details of how access was obtained remain undisclosed. The listing itself is therefore treated as an unverified claim by the threat actor rather than established fact.
The group behind it: interlock
Interlock is a ransomware operation that has been observed conducting double-extortion attacks: encrypting systems while also stealing data and threatening to publish it on a dedicated leak site if payment is not made. Like other groups of this type, it typically targets organisations across multiple sectors, posts victim names and sample claims on its site, and uses the threat of public exposure to increase pressure. Public reporting has associated interlock with a range of victims in government, healthcare and commercial environments, though each listing must be evaluated on its own evidence. In the present case the group asserts that it has already taken internal files and camera-related material from the Shelbyville Police Department; those assertions have not been independently verified in available public sources.
Shelbyville Police Department and its sector
The Shelbyville Police Department is a municipal law-enforcement agency responsible for protecting lives, preventing crime and investigating offences within its jurisdiction. Agencies of this kind routinely maintain records of incident reports, investigative files, body-worn and fixed-camera video, audio recordings, personnel information, and databases that may include personal identifiers of victims, witnesses, suspects and officers. Because these systems support both day-to-day operations and longer-term criminal justice processes, unauthorised access can compromise active cases, endanger individuals named in records, and erode public confidence. A breach claim against any police department therefore carries sector-wide significance: it raises questions about the resilience of systems that hold uniquely sensitive community data.
The information in question
The only data type explicitly named in the available record is “internal files exfiltrated in ransomware attack.” The interlock listing further claims that the attackers obtained access to cameras, all data and databases containing archived videos and crime footage, and all available cameras and devices recording audio or video. Exact contents, file counts and the identities of any individuals whose information appears remain unconfirmed. Organisations of this type typically hold:
- Investigative case files and incident reports
- Archived video and audio from body-worn, vehicle and fixed cameras
- Databases of personal identifiers linked to victims, witnesses and suspects
- Internal administrative and personnel records
Whether any or all of those categories were actually taken in this incident has not been independently established.
Why it matters
If the claimed material is authentic, individuals named in police records could face elevated risks of identity theft, targeted scams, doxxing or physical harassment. Compromised video and audio may reveal private moments, investigative techniques or the locations of vulnerable people. For the department itself, loss of control over evidence and operational data can hinder prosecutions, force costly remediation, and require notification of affected parties under applicable law. Even when the full scope is unknown, the mere listing of a police agency by a ransomware group creates lasting uncertainty for residents who must assume their information might be among the files until proven otherwise.
If your data was in this claimed breach
Because the number of people affected and the precise data elements remain unknown, anyone who has interacted with the Shelbyville Police Department—whether as a victim, witness, suspect, employee or resident—should treat the possibility of exposure seriously. Practical first steps include:
- Monitor financial and credit accounts for unusual activity and consider a fraud alert or credit freeze
- Be alert to phishing or social-engineering attempts that reference police matters or personal details
- Request a free annual credit report and review it carefully
- Change passwords on any accounts that may have reused credentials associated with the department
- Document any suspicious contacts and report them to the appropriate authorities
Readers can also run a free exposure scan of their email address to check whether their information has already surfaced in known breach data sets. Official updates from the Shelbyville Police Department or relevant state authorities should be followed as they become available; until then, caution and routine monitoring remain the most reliable protections.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Fargo Park District Listed by interlock Ransomware GroupCity of St Paul Listed by interlock Ransomware GroupCity of Peabody, MA Listed by interlock Ransomware GroupThe Salvation Army Listed by interlock Ransomware GroupLatest breaches
Publicly posted by interlock — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.