The Warren County Sheriff's Office in Kentucky detected a network breach in December 2025 and notified affected people in March 2026. Exposed data included names, Social Security numbers, driver's license numbers, and health insurance ID numbers. The ransomware group RansomHouse claimed credit.
What happened
The Warren County Sheriff's Office in Kentucky detected suspicious activity on its computer network on December 20, 2025. According to Comparitech, the office sent breach notification letters on March 5, 2026. The exposed data included names, Social Security numbers, driver's license numbers, and health insurance ID numbers. The office recommended that affected people enroll in credit monitoring. It did not disclose how many people were notified.
The ransomware group RansomHouse claimed credit for the intrusion. The group said it took 743 gigabytes of data, including weapon licenses, investigative materials, and a list of county informants with personal information. Those claims come from RansomHouse's own leak site and have not been independently confirmed.
Who was affected
Warren County includes Bowling Green, and the Sheriff's Office is the county's lead law enforcement agency. The compromised systems held records tied to both residents and the office's own operations. That means deputy and civilian-staff data can sit in the same breached dataset as resident data.
Why a breach like this reaches an officer's home life
The data taken in a government breach (names, dates of birth, Social Security numbers, and sometimes home addresses) is also the data that populates people-search and data-broker sites. A breach exposes records held inside a government system. Broker sites are a separate problem: they publish home addresses tied to your name where anyone can look them up. Credit monitoring addresses the identity-theft side of a breach. It does nothing about a published home address.
What Kentucky law does and does not cover
Kentucky has no Daniel's Law analog. Daniel's Law is a New Jersey statute that lets officers and certain public servants demand that data brokers remove their home address and phone number. Kentucky has no equivalent broker-removal right.
The state's Safe at Home program (KRS 14.300 to 14.318) lets certain crime victims use a substitute address on public records, including voter rolls. It covers victims of domestic violence, sexual assault, stalking, and human trafficking. It does not cover officers as a class.
Kentucky's Open Records Act exemption (KRS 61.878) can keep some personal information out of public records, but an agency applies it case by case rather than removing your information automatically.
What you can do
You cannot control whether a government system that holds your records gets breached. You can reduce what is publicly searchable about you elsewhere. Frontline Privacy finds your personal information on data-broker sites, files removal requests, and keeps checking so it can refile when the information reappears.
What reduces this risk
Kentucky has no Daniel's Law analog, so officers have no state right to demand removal from data brokers. The Safe at Home address confidentiality program (KRS 14.300 to 14.318) covers victims of domestic violence, sexual assault, stalking, and human trafficking, not officers as a class. The Open Records Act exemption (KRS 61.878) is applied case by case, not automatically. A government breach exposes identity data an officer cannot control. Broker sites are a separate, reducible exposure: they publish home addresses tied to a name, and removing those listings limits what someone can find by cross-referencing a leaked name.
Public sources
- A Kentucky Sheriff warns residents of data breach that leaked SSNs — Comparitech, 2026-03-06