On April 16, 2024, the French nonprofit organization ch-cannes.fr appeared on the LockBit 3.0 ransomware leak site, claiming that its internal files had been exfiltrated during a ransomware attack. The listing, hosted on the group’s onion domain and mirrored on ransomware.live, states that data was stolen and will be published if the organization does not meet the attackers’ demands. Anyone whose personal information appears in those files—whether as a donor, volunteer, employee, or program participant—now faces immediate exposure risks.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch ch-cannes.fr
Get alerted the next time ch-cannes.fr files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about ch-cannes.fr’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Reported Details from the Listing
The LockBit 3.0 leak page explicitly lists ch-cannes.fr as a victim and notes that internal files were allegedly exfiltrated. It does not disclose the exact number of records affected, the specific types of documents taken, or the ransom amount demanded. The disclosure indicates the data was obtained through a ransomware intrusion and is being held for extortion. No sample files have been published on the site as of the initial listing date, but the group’s standard practice is to release or auction stolen data after the deadline passes.
Why This Matters for You and Your Family
When a charity like ch-cannes.fr suffers a breach, the people most likely to be exposed are ordinary individuals: women who participated in cardiovascular health programs, donors who provided banking details, volunteers who submitted personal contact information, and staff whose employment records were stored on the same systems. Internal files often contain names, addresses, dates of birth, phone numbers, email accounts, and financial transaction records. Once these details leave the organization’s control, they can be cross-referenced with other leaks to build complete profiles that criminals use for identity theft, phishing, or targeted scams against you or members of your household.
The Doxxing and Identity-Chain Implications
Ransomware groups rarely limit themselves to one dataset. A single exposed email or phone number from this incident can be chained with credentials from earlier breaches, gaming account details, or social-media handles to create a persistent identity map. This chaining turns a donation record into a pathway for account takeovers, doxxing campaigns, or even physical harassment. Credential leaks like this one frequently cascade into gaming platforms, where children’s accounts become entry points for further targeting because the same password or recovery email is reused. The longer the data remains unmonitored, the more links attackers can forge between your online life and your real-world identity.