Skip to main content
FrontlinePrivacy
Address exposure

Warren County, Kentucky Sheriff's Office breach exposed Social Security and driver's license numbers

FILE 690Warren County, Kentucky2025-12-20
CLOSED

The Warren County Sheriff's Office in Kentucky detected a network breach in December 2025 and notified affected people in March 2026. Exposed data included names, Social Security numbers, driver's license numbers, and health insurance ID numbers. The ransomware group RansomHouse claimed credit.

What reduces this risk

Kentucky has no Daniel's Law analog, so officers have no state right to demand removal from data brokers. The Safe at Home address confidentiality program (KRS 14.300 to 14.318) covers victims of domestic violence, sexual assault, stalking, and human trafficking, not officers as a class. The Open Records Act exemption (KRS 61.878) is applied case by case, not automatically. A government breach exposes identity data an officer cannot control. Broker sites are a separate, reducible exposure: they publish home addresses tied to a name, and removing those listings limits what someone can find by cross-referencing a leaked name.

Public sources