On June 8, 2026, the Termite ransomware group listed the California Association of Food Banks on its leak site after exfiltrating internal files during a ransomware attack. The organization, which helps Californians apply for CalFresh food assistance and partners with food banks statewide since 2003, now faces public exposure of its internal documents. Anyone who has used CalFresh services, received assistance through CAFB-supported programs, or had their information shared with affiliated food banks could be affected.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Cal Fresh
Get alerted the next time Cal Fresh files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Cal Fresh’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting indicates that Termite posted details of the incident on its dark web leak site, accessible via the .onion address tracked by ransomware.live. The group claims to have exfiltrated internal files from the California Association of Food Banks. No specific victim count has been released, and the exact volume or sensitivity of the stolen data remains unclear from available reporting. The listing appeared on June 8, 2026, following the typical ransomware pattern of initial encryption demands followed by public shaming when payment is not made.
Why This Matters for You and Your Family
If your family has ever applied for CalFresh benefits, used a local food bank partnered with CAFB, or provided personal details such as names, addresses, phone numbers, dates of birth, or Social Security numbers to access food assistance, those records may now sit in a ransomware group's hands. Internal files from organizations like this often contain applicant information, case notes, eligibility documentation, and contact details for entire households. Once exposed, this data does not disappear. It circulates among criminals who combine it with other leaks to build profiles that lead to identity theft, fraudulent benefit claims, or targeted scams against you or your children.
The Doxxing and Identity-Chain Implications
Leaked assistance program records frequently include email addresses, phone numbers, and physical addresses that link directly to your online accounts. Criminals use these connections to map your digital footprint across social media, gaming platforms, and shopping sites. A single credential exposed in this claimed breach can unlock email accounts, which then reveal password-reset links for banking, government services, or your children's gaming profiles. Available reporting describes how such chains escalate quickly from data theft to full doxxing, where attackers publish personal details, harass family members, or sell the compiled dossiers on underground markets.