In March 2026, a ransomware attack disrupted Jackson County, Indiana's computer network and drew the FBI and the Department of Homeland Security. The same month, DeKalb County, Indiana disclosed a separate breach that may have exposed residents' Social Security and driver's license numbers.
What happened
In late March 2026, the FBI, the U.S. Department of Homeland Security, and the Indiana Department of Homeland Security began investigating a ransomware attack on Jackson County, Indiana's computer network. The attack crippled Jackson County Sheriff's Office systems. County officials said they would not pay a ransom and reported no loss of hardware, data, or taxpayer funds.
Around the same time, DeKalb County, Indiana disclosed a separate breach. The county said an unauthorized party may have copied files from its network between August 21 and September 25, 2025. The exposed information could include names, Social Security numbers, driver's license or identification card numbers, and financial account numbers.
What actually leaked
The two incidents are different. Jackson County describes a system disruption, not a confirmed loss of records. DeKalb County confirmed that personal information may have been copied and told affected residents to watch for identity theft.
County networks hold data on employees as well as residents. Deputies, civilian staff, and their family records often sit in the same systems that handle resident services. A breach that reaches those systems can expose the same home addresses and identifiers that make an officer a target.
What this means for you
If you are an Indiana deputy, judge, or county employee, state law gives you a few tools.
Ind. Code § 5-14-3-4(a)(23) bars a public agency from releasing records that identify a covered person's home address when the request comes from an offender or an offender's agent. Covered people include law enforcement, correctional, probation, and community corrections officers, judges, and their family members. It is not a blanket exemption from every public-records request, so confirm how your agency applies it.
Ind. Code § 36-1-8.5-7 lets a covered person, including law enforcement officers, judges, and firefighters, submit a written request to keep their home address off a county's public property database website. A county may charge a reasonable fee.
Ind. Code § 35-45-2-1 is Indiana's criminal intimidation law. It makes it a crime to threaten someone in order to place them in fear. A 2026 doxxing law (Senate Bill 140), effective July 1, 2026, builds on that threat definition and makes it a crime to post someone's personal information, such as a home address, phone number, or employer, to communicate a threat. It is a criminal referral, not a way to make a broker listing come down.
These tools cover data the state and county hold. They do not reach data broker and people-search sites. After a breach, leaked names, addresses, and identifiers get matched against existing broker profiles and republished. That layer is what keeps a home address searchable long after the county closes its investigation.
Frontline Privacy finds those broker listings, files removals, and keeps checking for records that come back.
What reduces this risk
Indiana law gives public servants a few real tools. State code bars a public agency from releasing a covered person's home address when the request comes from an offender or an offender's agent, covering law enforcement, correctional, probation, and community corrections officers, judges, and their family members (Ind. Code § 5-14-3-4(a)(23)). A covered person can also submit a written request to keep their home address off a county property-database website (Ind. Code § 36-1-8.5-7), and the state's intimidation law criminalizes threats meant to place someone in fear (Ind. Code § 35-45-2-1). None of them remove personal information already posted on data broker and people-search sites, which is where leaked identifiers resurface after a breach.