On February 11, 2026, the Aeromedical Society of Australasia appeared on the LockBit 5 ransomware leak site with internal files listed for public download after the non-profit failed to meet the attackers’ demands.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch aeromedsocaustralasia.org
Get alerted the next time aeromedsocaustralasia.org files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about aeromedsocaustralasia.org’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting indicates the Aeromedical Society of Australasia, a membership organisation supporting aeromedical professionals across Australia and New Zealand, had data exfiltrated during a ransomware incident. The LockBit 5 group posted proof of the breach on its dark-web leak site, showing samples of internal documents. No exact victim count has been released, and the precise number of records exposed remains unclear. Available reporting describes the data as internal files rather than a structured database of member details, though such files often contain names, contact information, medical credentials and operational records. The organisation has not issued a public statement confirming the extent of the compromise.
Why This Matters for You and Your Family
When a professional society like this is breached, the people affected are often ordinary members — doctors, nurses, paramedics and support staff who rely on the organisation for certification, event registration and industry updates. If your name, email, phone number or address appears in those internal files, the information can be combined with data from earlier breaches to build a detailed profile. Credential leaks like this one frequently cascade into account takeovers on personal email, banking portals and even gaming platforms used by you or your children. Once attackers control an email account tied to multiple services, they can reset passwords elsewhere, request sensitive documents, or sell the access on underground forums. For families this means heightened risk of identity theft, financial fraud and unwanted exposure of personal or children’s information that should stay private.
The Doxxing and Identity-Chain Implications
Ransomware groups rarely stop at posting generic files. They search for any link between organisational data and real people. A membership list that connects an email address to a name, workplace and phone number can be chained with gaming usernames, social-media handles or family addresses found in other breaches. This creates an identity chain that turns a single leak into long-term doxxing material. Public reporting indicates that children’s gaming accounts are especially vulnerable because parents often reuse credentials or link family email addresses to those platforms. The result can be harassment, swatting or targeted scams that reach beyond the original victim to every member of the household.