Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
Columbus did not continue its lawsuit against David Leroy Ross Jr. The city sued Ross on August 29, 2024, after he examined data posted by the Rhysida ransomware group and used samples to challenge Mayor Andrew Ginther’s description of the attack. Columbus later agreed to dismiss the civil case while continuing restrictions on the publication of specific sensitive records.
The agreement preserved Ross’s ability to discuss the intrusion and the categories of information exposed. It prohibited him from publicly disseminating records containing information such as Social Security numbers, driver’s-license numbers, financial details, medical information, and data from certain police and prosecutor databases.
What happened to Columbus?
On July 18, 2024, Columbus detected an abnormality in its computer systems and severed internet connectivity while responding. In its initial public account, the city described the event as an attempted disruption by a foreign cyber threat actor that might have been preparing to deploy ransomware and demand payment.
Free tools Windows power users keep installed
One-click scans. No signup required.
The city said its investigation was continuing and that it was still determining how much information attackers may have accessed. Later reporting said the Rhysida ransomware group claimed responsibility, claimed to have obtained about 6.5 terabytes of data, and published some of it after an attempted auction failed. The 6.5-terabyte figure should be understood as a claim attributed to the attackers or subsequent reporting, not necessarily as an independently verified measurement. Columbus’s incident notice used more cautious terms including “cybersecurity incident” and “cyber intrusion.”
#1 Best Overall
That distinction matters. A cyber intrusion can involve unauthorized access or data theft without proving that every affected system was encrypted. “Ransomware attack,” “data exfiltration,” “leak,” and “encryption” describe different parts of an incident.
What did Mayor Ginther say?
On August 13, 2024, Mayor Andrew Ginther said the city’s forensic investigation found that sensitive files were encrypted or corrupted and therefore unusable to criminals. He suggested that the data’s lack of integrity could explain why the ransomware group did not sell it.
That was the city’s characterization, not an uncontested finding established in the public record. Ross later challenged it, and samples examined by local media reportedly appeared readable and contained sensitive information. A precise account therefore needs to distinguish between what the city said its investigation found and what Ross and reporters said they observed in samples.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Who is David Leroy Ross?
Ross is a Columbus resident and cybersecurity researcher who used the alias Connor Goodwolf in media appearances. He examined files that Rhysida had posted on the dark web and contacted local news organizations.
According to contemporary reporting, Ross showed screenshots and samples suggesting that at least some of the exposed files were intact and readable. Reported examples involved city employees, residents, police officers, crime victims, domestic-violence cases, and criminal investigations. Those examples do not establish that every file in the attackers’ dataset was authentic, complete, current, or readable.
Rank #2
Ross’s public role was more specific than simply “exposing the breach.” He publicly challenged the city’s description of the incident and demonstrated what some of the posted material appeared to contain. Civil-liberties advocates and some coverage described him as a whistleblower, but that is a characterization rather than an established legal status.
What did Ross disclose?
The central issue was the difference between discussing the breach and redistributing the records taken during it.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchPC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11- Discussion: Ross could describe the cyber intrusion and the types of information that appeared to be exposed.
- Underlying records: The eventual agreement restricted public dissemination of specified sensitive files and information.
Showing evidence to journalists can help establish whether a government’s public account is accurate. But when the evidence contains personal information, even limited disclosure can create additional privacy and safety risks for the people named in the records. The existence of a file in an attacker’s leak also does not prove that every field in it is accurate or that the material can lawfully be republished.
Readers should not search for or download the leaked material. Publishing Social Security numbers, addresses, medical information, financial data, police-identifying information, or crime-victim details can compound the original harm.
Why did Columbus sue?
Columbus’s complaint reportedly included claims involving alleged criminal acts, invasion of privacy, negligence, and civil conversion. The city argued that Ross had downloaded stolen data from a dark-web site, stored it locally, and provided it to media organizations.
The city also argued that Ross’s specialized expertise and tools made the information more accessible to people who otherwise might not have found it. The city attorney’s public position was that the lawsuit focused on preventing dissemination of stolen law-enforcement and personally identifiable information—not on suppressing criticism of city officials or discussion of the breach.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →Ross and civil-liberties advocates saw a different danger: that suing the person who challenged the official account could discourage speech about a matter of public concern. Both concerns can exist at the same time. A government may have a legitimate interest in preventing the spread of victims’ records, while an emergency court order aimed at a researcher can raise serious free-speech and public-accountability questions.
What did the judge order?
On August 29, 2024, a Franklin County judge granted Columbus’s request for a temporary restraining order. The order was issued ex parte, meaning Ross did not initially have an opportunity to contest it before it was entered.
The order prohibited Ross from:
- accessing city files posted to the dark web;
- downloading those files; and
- disseminating them.
This was not the same as a court order forbidding Ross from saying that Columbus had suffered a cyber intrusion. The later agreement expressly preserved his ability to discuss the incident and explain the categories of data that appeared to be exposed. Calling the temporary order an absolute “gag order” would therefore be imprecise unless that description is attributed to a particular advocate or legal commentator.
How did the lawsuit end?
| Date | What happened |
|---|---|
| July 18, 2024 | Columbus detected an abnormality and began its incident response. |
| July 29, 2024 | The city publicly described an attempted disruption and possible ransomware deployment. |
| August 8, 2024 | Rhysida reportedly released part of the stolen data after an unsuccessful auction. |
| August 13, 2024 | Ginther said sensitive files were encrypted or corrupted and unusable to criminals. |
| August 29, 2024 | Columbus sued Ross and obtained the temporary restraining order. |
| September 11, 2024 | The parties reached an agreement on a preliminary injunction preserving discussion of the breach while restricting specified sensitive information. |
| October 25, 2024 | Columbus announced an agreement under which it would dismiss the civil lawsuit while restrictions continued through an agreed permanent injunction. |
In its October 25 announcement, the city said the agreement had been filed with the court and was awaiting the judge’s approval at that time. The announcement and the dismissal should not be confused with a judicial finding that either side’s public narrative was correct.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problemsThe agreement continued to prohibit Ross from publicly disseminating specified sensitive information, including Social Security numbers, driver’s-license numbers, financial and medical information, and data from the city’s MATRIX prosecutor and crime databases. It preserved his ability to discuss the cyber intrusion, including with the media, and to describe the types of information exposed.
How many people were affected?
Later reporting put the number of potentially affected individuals at approximately 500,000. That figure should be attributed to breach-notification reporting unless an official city notice or regulatory filing confirms the exact count.
The affected population may have included city employees, residents, nonresidents, municipal-court users, and others whose information had been provided to the city or court. The relevant question is not simply whether a person’s name appeared in a leaked file. It is whether personal information was confirmed exposed, what categories were involved, and whether the information was sufficiently reliable for identity theft or other misuse.
Columbus offered credit monitoring to affected residents and other people whose information had been shared with the city or municipal court, according to WOSU’s account of the settlement. Anyone who received an official notice should use the contact details in that notice rather than relying on links in unsolicited emails or messages.
What remains disputed or difficult to verify?
- The exact amount of data stolen.
- The percentage of files that were intact and readable.
- The complete list of affected systems and databases.
- Whether every category of sensitive information described in news reports was confirmed by Columbus.
- Whether the city’s early “encrypted or corrupted” assessment reflected the full dataset, only part of it, or an interpretation later challenged by additional evidence.
- The exact final wording and docket status of the permanent injunction unless the signed court order is consulted directly.
The city continued cybersecurity investigation, breach-related legal work, and response contracting after the settlement, according to a February 2025 Columbus City Bulletin. Continued response work does not, by itself, resolve the dispute over how the original data exposure should be characterized.
Why the case matters
The dispute presents a difficult line for governments, researchers, journalists, and courts.
Researchers and reporters may need to test an agency’s description of a breach. Without evidence, the public may not know whether “no usable data” means that files were actually unreadable or merely that the agency had not found evidence of misuse. But proving the point by retaining or distributing raw records can expose victims to further harm.
The legal questions include whether downloading publicly posted stolen data can constitute conversion or another civil tort; whether a researcher’s purpose matters; whether showing a minimally redacted sample differs from publishing a full dataset; and how narrowly a court can restrict publication of unlawfully obtained personal information while allowing discussion of the government’s response. Those are fact-specific questions for the court and qualified legal commentators, not conclusions that can be drawn solely from the public announcements.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →For public agencies, the episode also illustrates the importance of prompt, precise breach communication: separating confirmed exposure from potential exposure, explaining what “encrypted” or “corrupted” means, notifying affected people when required, and creating channels for researchers to report evidence without distributing victims’ data.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

