On October 21, 2023, the Canadian Hearing Society (CHS) appeared on the LockBit 3.0 ransomware leak site, with the group claiming to have exfiltrated internal files during a ransomware attack. The listing states that CHS, which provides services supporting the independence of deaf, deafened, and hard-of-hearing individuals across Canada, failed to meet the attackers’ demands. As a result, anyone whose personal information or employment records sit inside those systems now faces the concrete risk that their data has been stolen and may surface publicly.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 582 companies.
See what is exposed about you — free scan →Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.
Reported Details from the Listing
The LockBit 3.0 leak page, still accessible via its onion address as of the initial publication date, asserts that internal files were successfully exfiltrated. It does not specify the volume of data taken, the exact types of records involved, or the number of individuals affected. The disclosure indicates the Canadian Hearing Society was given a deadline to pay or face publication; when that deadline passed without resolution, the group posted proof of compromise and samples. No official breach notification from CHS had been located in public regulator filings at the time the listing went live, leaving many core facts unknown. The listing itself remains the primary public record of the incident.
Why This Matters for You and Your Family
If you or a family member have ever received services from the Canadian Hearing Society, worked there, or had your information shared with the organization, your data may now sit in an attacker-controlled archive. Internal files in a healthcare-adjacent nonprofit like CHS frequently contain names, contact details, dates of birth, government identifiers, medical or accommodation notes, and employee payroll information. Even partial exposure of such records can fuel identity theft, targeted fraud, or harassment. Because the exact scope remains undisclosed, the safest assumption is that any record touching the organization could be at risk.
The Doxxing and Identity-Chain Risks
Ransomware groups rarely limit themselves to one dataset. A single leaked email or phone number from the CHS breach can be chained with credentials from earlier breaches, gaming accounts, or social-media handles to build a complete profile. Attackers then sell or weaponize these chains for doxxing, SIM-swapping, or account takeovers. Children’s gaming accounts are especially vulnerable because parents often reuse passwords or recovery emails tied to family service records. The result is a cascading exposure that can affect every member of a household long after the initial breach is forgotten.