USGS Listed by fog Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The USGS Listed by fog Ransomware Group (reported July 12, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
Ransomware groups continue to pressure public-sector and scientific organisations by claiming data theft and threatening publication, a pattern that has become a routine feature of the current threat landscape. In this environment, even listings that lack independent confirmation can create lasting uncertainty for staff, partners and anyone whose information might sit inside internal systems.
On July 12, 2023, the United States Geological Survey, known as USGS, was listed by the ransomware group fog. The group claims that internal files were exfiltrated in a ransomware attack. The number of people affected remains unknown, and public detail beyond the listing itself is limited. The incident matters because USGS holds scientific, operational and administrative data whose exposure could affect research integrity, government operations and individuals connected to the agency.
Breaking down the breach
Public reporting on July 12, 2023, recorded that USGS had been listed by the fog ransomware group. According to the available summary, the claim centres on internal files said to have been exfiltrated during a ransomware attack. No confirmed figure for the number of people affected has been released. The precise timing of any intrusion, the initial access method, the duration of unauthorised access, and the full scope of systems involved have not been disclosed in the material available for this account.
The listing itself constitutes a claim by the group rather than an independently verified confirmation of every asserted detail. Organisations named on ransomware leak sites sometimes later confirm an incident, dispute the scale, or provide additional context; in this case, the public record as summarised simply notes the listing and the assertion that internal files were taken. Without further official disclosure, the exact sequence of events and the completeness of any data theft remain unconfirmed.
The group behind it: fog
Fog is a ransomware operation that has appeared in public reporting as a group that encrypts victim environments and exfiltrates data to increase pressure for payment. Like many contemporary ransomware actors, it has been associated with double-extortion tactics: threatening to publish stolen material if demands are not met, and using dedicated leak sites or similar channels to name victims. Public knowledge of the group centres on this operational pattern rather than on any single unique technical signature that would distinguish every campaign.
In the present matter, fog’s listing of USGS should be read as the group’s claim. No statement from the group beyond the fact of the listing and the assertion of internal-file exfiltration is treated here as established fact about this specific victim. Prior activity attributed to fog in open sources follows the familiar ransomware playbook of intrusion, data theft, encryption where achieved, and public naming of organisations. Those general patterns supply context; they do not fill gaps in what has been reported about USGS.
Who is USGS?
USGS is the United States Geological Survey, a federal scientific agency within the U.S. Department of the Interior. It conducts research and monitoring related to natural hazards, water resources, energy and mineral resources, ecosystems, and the structure and history of the Earth. Its work supports emergency management, environmental policy, land-use planning and a wide range of public and private decision-making.
Agencies of this type typically maintain research datasets, geospatial and sensor information, administrative records, contractor and employee information, and internal correspondence and project files. A breach affecting such an organisation is consequential because the data can include both publicly oriented scientific material and non-public operational or personal information. Disruption or exposure can affect ongoing studies, inter-agency coordination and the privacy of people who interact with the agency as staff, collaborators or members of the public.
What data was at risk
The facts available name the exposed material as internal files exfiltrated in a ransomware attack. No further breakdown of file categories, record counts or specific data elements has been disclosed. The number of people affected is unknown.
Organisations such as USGS ordinarily hold a mix of scientific and technical data, administrative and human-resources records, procurement and contractor information, and internal communications. It is reasonable to expect that internal files could touch some of those categories, yet it would be inaccurate to state that any particular type of personal or sensitive record was confirmed as exposed. The exact contents remain unconfirmed; only the group’s claim of internal-file exfiltration is on the public record summarised here.
The real-world impact
For individuals, the practical risk depends on whether personal information was present in the taken files and whether those files later circulate. Possible consequences include unwanted contact, attempted fraud using workplace or identity details, or long-term uncertainty about what may have been exposed. Because the scale and content are undisclosed, people connected to USGS cannot yet gauge personal exposure with precision.
For the organisation, a claimed exfiltration of internal files raises concerns about operational continuity, the integrity of research and administrative processes, and the need to review access controls and incident-response posture. Even when encryption or system downtime is not publicly detailed, the reputational and coordination costs of a ransomware listing can be significant. Partners and other agencies may also need to reassess shared access or data-exchange arrangements until more is known.
Were you affected?
If you work with, contract for, or have supplied personal information to USGS, treat the situation as a prompt to increase vigilance rather than as proof that your data was taken. Monitor financial and account statements for unfamiliar activity, be cautious of unexpected messages that reference the agency or this incident, and consider placing fraud alerts with credit reporting services if you believe sensitive identifiers may have been involved. Change passwords on related accounts and enable multi-factor authentication where available.
You can also run a free exposure scan of your email address to check whether your information has already surfaced in known breach datasets. That step does not confirm or rule out involvement in this specific incident, but it provides a practical way to see whether your credentials or personal details appear in previously compiled breach collections and to take follow-up protective measures if they do.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Cucamonga Valley Water District (cvwdwater.com) Listed by fog Ransomware GroupNewtown Friends School (newtownfriends.org) Listed by fog Ransomware GroupUniversity Diagnostic Medical Imaging, PC (udmi.net) Listed by fog Ransomware GroupEl Camino Real Academy (elcaminorealacademy) Listed by fog Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the USGS Listed by fog Ransomware Group →
Publicly posted by fog — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.