The Morton Grove Park District Listed by Deadlock Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The Morton Grove Park District was listed by the Deadlock ransomware group on July 10, 2026, after internal files were exfiltrated in a ransomware attack; the number of people affected is not yet known. If you have records or accounts with the district, review any notices from them and consider changing passwords or monitoring your accounts for unusual activity.
What happened
The listing indicates that internal files were exfiltrated during a ransomware attack. The scale of the operation, the precise date of any intrusion, and the method of access remain undisclosed. The group claims responsibility through its leak site, but no independent confirmation of the data volume or contents has been made public.
Inside Deadlock
Deadlock is a ransomware operation that has been publicly tracked for several years. The group typically gains access through compromised credentials or unpatched systems, deploys encryption on target networks, and then lists victims on its site when ransom demands are not met. Prior activity attributed to the group has involved municipal and public-sector targets, with data posted after negotiations failed.
About The Morton Grove Park District
The Morton Grove Park District is a municipal agency established in 1951 and governed by five elected commissioners under Illinois state law. Park districts of this type manage recreational facilities, youth programs, and community services, which requires them to collect and retain records on residents, employees, vendors, and program participants.
What data was at risk
Reports state that more than 50 GB of internal files were taken. The exact categories of information have not been verified by the organization.
- Personal and sensitive information on employees
- Personal and sensitive information on clients and suppliers
- Documents related to financial plans
What's at stake
Records held by a park district can include names, addresses, contact details, program enrollment information, and financial documentation. Exposure of such material can lead to targeted fraud attempts, identity misuse, or unwanted contact. For the agency, the incident may require extended forensic review, notification procedures, and adjustments to existing security controls.
If your data was in this claimed breach
Begin by monitoring accounts for unusual activity and enabling multi-factor authentication where available. Request a copy of any records the district holds about you and review them for accuracy. You can also run a free exposure scan of your email address against known breach data to see whether your information appears in other public listings.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
La ville de Ouangani Listed by Deadlock Ransomware GroupUFL Listed by Deadlock Ransomware GroupPicassent Listed by Deadlock Ransomware GroupAksv Listed by Deadlock Ransomware GroupLatest breaches
Publicly posted by deadlock — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.