Autistici/Inventati Named a Terror Group: Does the ICE Doxing Affect You?
If you are a customer of Autistici/Inventati Named a Terror Group, here’s what is being claimed, and what it would mean for you.
On August 26, 2026, the U.S. government designated Autistici/Inventati a terrorist organization, saying its hosting and email tools were used to publish ICE officers’ personal information and to call for attacks at their homes. The group denies the charges. This is not a consumer data breach; most ordinary people are not in the material the government described.
— from the group that posted this listing’s own leak-site posting. This is the group’s claim, quoted verbatim; it is not GalaxyWarden’s reporting and has not been independently verified.
Editor’s note: The claims described below originate from a ransomware group’s leak-site posting and have not been independently verified by GalaxyWarden. A listing of this kind is an assertion made by the group during an extortion attempt. It is not evidence that a breach occurred, and we report it as a claim rather than as a finding.
Autistici/Inventati Named a Terror Group customer?
See what’s already exposed about you — free, 15sWe check your email against known public breach records and the sites that publish your address, then show you what to do about each one. We don’t hold this company’s data. No account, no card.
Here for work? Check a company domain’s exposure.
On August 26, 2026, the U.S. State Department and Treasury Department designated Autistici/Inventati (the A/I Collective) a Specially Designated Global Terrorist. Official statements say the collective provided encrypted email, chats, and web hosting — including noblogs.org — that far-left extremist groups used to share target information. The State Department’s public fact sheet says Oregon-based Rose City Antifa used those tools to publish doxing lists and illegally obtained personal information of ICE officers, along with calls for attacks on agents in the streets and in their homes. It says an Atlanta anarchist cell used the same tools to spread doxing lists and private information. U.S. transactions with A/I are now blocked, and assets can be frozen.
Autistici/Inventati denied the allegations as false and politically motivated, said it offers tools for digital self-defense and free communication, and said it will keep operating. The Daily Wire, citing a State Department official, and Fox News, citing a State Department memo, reported extra details that do not appear in the public fact sheet, including that names and other details of 48 ICE and DHS officers were published and that license-plate photos were shared. Those extra specifics have not been itemized in the government’s public notices.
This is not a store, bank, or password breach
Most coverage leads with the terrorist label, or with a fight over far-left groups. That framing makes this sound like foreign policy, or like a leak from a company that has your account. It is neither.
The government’s own fact sheet is describing something narrower and more physical: personal information of federal immigration officers was published, including material that points to where they live, together with calls to attack them in the streets and in their homes. For those officers and the people who live with them, that is a safety problem that does not expire when the news cycle moves on. Designating the host does not unsay a home address.
Advertisement
Know the day any company files a breach.
Every SEC 8-K Item 1.05 and state breach notification — dated, sourced, and delivered by email + a JSON API the day it posts. Track any company, not just the ones in the news.
GalaxyWarden Signals and RecentBreaches share common ownership.
For everyone else, the usual fear is a category error. This is not a dump of customers from a retailer, a hospital, a bank, or a password manager. The State Department did not say that thousands of ordinary inboxes were emptied into public view. It said a specific hosting service was used to spread target lists about ICE. If you never worked in federal immigration enforcement and never signed up for Autistici email or noblogs.org, the incident the government described is not a file with your name in it.
There is a second, separate issue only for people who did use those services from the United States. The legal change is that A/I is now a designated terrorist organization, which means Americans are not allowed to pay it or otherwise deal with it. That is not the same thing as “your private messages were posted.” Mixing those two up is why this story feels like it might include you when it probably does not.
What to actually expect
- You should not expect a breach letter, a credit-monitoring offer, or a notice from a company you shop with. Nothing in the official statements describes a leak of ordinary customer records.
- Posted information about officers will keep circulating. Listing the host as a terrorist group does not pull copies, screenshots, or reposts off the internet.
- If you are a U.S. person who used Autistici email or noblogs.org, the near-term change is practical and legal: you can no longer pay or do business with that provider, and the service may become unreliable. That is separate from whether anyone published your messages.
- There is no public roster you can search to see whether “you were in this,” and no scan that can honestly answer that question. Treat that kind of lookup as a dead end.
What you can and cannot fix
What was published cannot be undone. If a name and a home address went out on a doxing list, they are out. Mirrors, archives, and screenshots cannot be recalled. No designation, takedown request, or paid “removal” service puts that material back in the bottle. Do not pay anyone who claims they can delete the original posts or confirm that you were or were not listed.
- If you have no connection to ICE or DHS and never used Autistici or noblogs.org: there is nothing to fix for this incident. Changing passwords or freezing credit because of this story does not address anything the government described.
- If you are an immigration officer, live with one, or already know your information was posted: the real lever is shrinking the rest of your public footprint. A bare leaked record becomes dangerous when it is joined to people-search listings that add relatives, phone numbers, employers, and previous addresses. Those listings, unlike the leaked posts, can actually be removed. Opt out of the major people-search sites first; that is the part you can still cut down.
- If you used A/I services from the United States: stop using them and stop paying them. Move your mail and sites to another provider. That does not unsay anything already published. It stops a now-illegal relationship and a service that may not be there tomorrow.
- Do not chase individual officer details, lists, or “leaks” in order to check a name. Repeating that material does not protect anyone, and it is not how you find out whether this touched you.
What the free scan actually returns
Found on people-search siteswe remove these
These listings are live, public, and legal to remove — and removing them is what we do.
Found in breach recordsverifiedreported — unverified
Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.
Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.
For security and vendor-risk teams: get an alert the day a vendor you watch files a breach with a US regulator or the SEC — the filing itself, dated and sourced, plus an API. GalaxyWarden Signals →
A staff address in a leak usually means a third party was breached, not you — check your own domain’s exposure. Exposure Monitoring →
Report details & sourcing
Related breaches
Flock Safety CEO address posts: what is confirmed and whether it affects you
In late August 2026, posts on X claimed to share Flock Safety CEO Garrett Langley’s home address aft…
ICE/DHS Agents Personal Data Leak — January 2026
A whistleblower posted personal data on approximately 4,500 ICE/DHS agents to a doxxing site in Janu…
Trezor Shipping Data Breach — 13,689 Hardware Wallet Buyers, Home Addresses Included
ShipMonk, a logistics provider used by Trezor, was breached through a vulnerability in the third-par…