On August 1, 2024, the summer camp operator Camp Susque appeared on the leak site of the Medusa ransomware group. The listing states that internal files totaling 48.9 GB were exfiltrated during a ransomware attack. The Pennsylvania-based organization, which has offered wilderness trips, family camps, winter camps, homeschool classes, field trips, and retreats since 1947, has not yet published its own breach notification, leaving the exact number of affected individuals unknown.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Camp Susque
Get alerted the next time Camp Susque files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Camp Susque’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Details in the Leak-Site Listing
The Medusa leak site entry states that attackers gained access to Camp Susque’s corporate systems and removed 48.9 GB of internal files. The disclosure does not specify the precise data types contained in the archive, nor does it list individual record counts. It simply states that the material was stolen and will be published if the camp does not meet the group’s extortion demands. The listing includes the camp’s physical address at 47 Susque Camp Rd, Trout Run, Pennsylvania, and notes that the organization employs 16 people. No sample files have been released publicly at the time of this writing, so the full scope of personal information at risk remains unclear.
Why This Matters for You and Your Family
If you or your children have attended Camp Susque programs, your personal details may sit inside the stolen files. Camps routinely collect names, home addresses, phone numbers, email addresses, dates of birth, emergency contacts, medical information, and sometimes Social Security numbers for minors. When such records leave an organization without proper encryption, they become raw material for identity theft, phishing campaigns, and long-term fraud. Even if the exact contents are not yet public, the 48.9 GB volume suggests a substantial cache of operational and participant data. Families who trusted the camp with sensitive child-related records now face the reality that those records could surface on criminal forums at any time.
Doxxing and Identity-Chain Risks
Ransomware leaks rarely stop at one company. A single exposed email or phone number can be cross-referenced with gaming usernames, social-media handles, and school records to build a complete profile of you and your household. Children’s information is especially valuable to attackers because it can link to family financial data and persist for years. Credential leaks from summer-camp systems often cascade into gaming-account takeovers, where stolen passwords grant entry to Roblox, Minecraft, or Discord profiles that contain additional personal details and payment methods. These chains turn one breach into repeated harassment or financial loss. Continuous monitoring that maps handles to real identities is one of the few practical defenses against such expanding exposure.