On September 13, 2025, the American Association on Health and Disability appeared on the leak site of the sinobi ransomware group in a listing claiming internal files were exfiltrated during a ransomware attack.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.
What Public Reporting Shows
Public reporting indicates that sinobi listed AAHD on its dark web leak page, claiming to have stolen internal documents. The organization, which focuses on health promotion, wellness programs, policy advocacy, research, and publication of the peer-reviewed Disability Health Journal, serves individuals with disabilities, healthcare professionals, researchers, and policymakers. Available reporting does not yet specify the exact number of records involved or the full list of data types exposed, though ransomware incidents of this nature typically include documents containing personal information, donor records, employee details, or program participant data. No confirmed deadline for extortion payments has been publicly detailed in available sources.
Why This Matters for You and Your Family
When organizations like AAHD suffer breaches, the people whose information they hold — program participants, donors, employees, or newsletter subscribers — can face direct risk. Internal files exfiltrated often contain names, addresses, medical conditions, contact details, or financial information that criminals can use for identity theft, phishing, or targeted scams. If you or a family member have interacted with disability health programs, advocacy groups, or similar nonprofits, your data may now be in criminal hands. These incidents rarely stay contained; once files appear on leak sites, copies spread quickly across underground forums.
The Doxxing and Identity-Chain Implications
Stolen internal files frequently link email addresses, phone numbers, physical addresses, and usernames. Criminals chain these pieces together with data from other breaches to build complete profiles. A single exposed email can lead to account takeovers on personal services, which then reveal more data and escalate into full doxxing. Gaming accounts belonging to you or your children are especially vulnerable because kids often reuse credentials or email addresses tied to family accounts. Public reporting shows these credential leaks regularly cascade into harassment, swatting, or financial fraud when identity chains are mapped.