In July 2020, the Minnesota Reformer reported that personal information for roughly 1,500 first responders, corporate security staff, and stadium security personnel tied to the Hennepin County Sheriff's Office had been published online. The data came from a breach of the county's web vendor, part of the larger BlueLeaks release.
What happened
The exposed data was housed at Netsential, a Houston web-services firm used by the Minnesota Bureau of Criminal Apprehension and the Hennepin County Sheriff's Office. A threat actor breached Netsential in mid-2020, and on June 19 the activist group Distributed Denial of Secrets published nearly 270 gigabytes of files from more than 200 U.S. law enforcement agencies. The release became known as BlueLeaks.
On July 10, 2020, the Minnesota Reformer reported that the Hennepin County portion of the leak included names and contact information for approximately 1,500 first responders, corporate security personnel, and stadium security staff. Reported fields included names, titles, ranks, employers, addresses, mobile and pager numbers, email addresses, and IP addresses. A larger trove tied to ICEFISHX, a Minnesota Fusion Center alert system, exposed data on more than 9,000 government and industry personnel.
The leak came during a period of intense public attention on Minneapolis-area law enforcement following the killing of George Floyd in May 2020.
How it started
The breach traced to the vendor, not to the Bureau of Criminal Apprehension or the Sheriff's Office directly. That is worth noting. Officer data lives in many hands: training systems, accreditation bodies, payroll vendors, body-camera vendors, and scheduling tools. Each one is a potential source of a leak.
Once the files were published, they were copied and mirrored widely. At that point the original leak cannot be pulled back. What can be controlled is republication: the broker and people-search pages that pick up leaked details and attach them to your name and address.
What this means for you
Minnesota gives you real state-level options. Safe at Home, run by the Secretary of State, assigns you a substitute PO Box address that public and private entities must accept in place of your home address; your real address stays out of their records (Minn. Stat. Ch. 5B). A related provision classifies a Safe at Home participant's location data in government records as private (Minn. Stat. § 13.045). Separately, you can ask the state to keep your driver's-license residence address private for your or your family's safety (Minn. Stat. § 171.12).
Those programs stop the state from publishing your address. They do not stop a data broker from republishing it after a leak. Broker removal is the layer that has to stay current, because a home address ties strangers to the people living there. Frontline Privacy files the removals and re-files when listings come back.
About these case pages: We cover only incidents that have already been publicly reported, we do not name private victims, and every claim links to a public source.
What reduces this risk
When a vendor your agency relies on is breached, your information can end up online without you knowing. Minnesota's Safe at Home program (Minn. Stat. Ch. 5B) gives you a substitute address that public and private entities must accept in place of your home address. It does not reach what data brokers republish from a leak like this one. Frontline Privacy finds those broker listings, files removal requests, and keeps checking for the records that come back.
Public sources
- Personal information of Minnesota law enforcement, critical infrastructure personnel published online after massive hack — Minnesota Reformer, 2020-07-10
- 'BlueLeaks' Exposes Files from Hundreds of Police Departments — KrebsOnSecurity, 2020-06-22