On July 11, 2024, the non-profit organization CODAC appeared on the leak site operated by the qilin ransomware group. The listing states that internal files were exfiltrated during a ransomware attack on the Rhode Island-based provider of addiction treatment, recovery, and prevention services. The disclosure does not specify the number of individuals affected or list exact data types beyond claiming that internal files were taken.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch codacinc.org
Get alerted the next time codacinc.org files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about codacinc.org’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Primary Disclosure Details
The qilin leak site entry, accessible via the .onion address tracked by ransomware.live, explicitly names codacinc.org and asserts that data was stolen in the course of a ransomware operation. No sample files are publicly shown in the listing itself, and the notification does not quantify records or name the precise systems compromised. The disclosure indicates the incident occurred prior to the July 11 publication date, but provides no timeline for initial access or exfiltration. Public reporting on qilin listings consistently treats these postings as evidence that sensitive internal documents have been removed from the victim environment.
Why This Matters for You and Your Family
If you or anyone in your household has received treatment, counseling, or support services from CODAC in the past 50 years, your personal information may now sit in an attacker-controlled archive. Health-related records held by addiction-treatment providers routinely contain names, dates of birth, Social Security numbers, contact details, insurance information, and clinical notes. Exposure of such material creates immediate financial and reputational risk because criminals can use it to file fraudulent tax returns, open accounts in your name, or pressure you with the threat of releasing private medical details. Even when the leak-site listing does not detail what was taken, the claimed exfiltration of internal files means you must treat your data as public.
Doxxing and Identity-Chain Implications
Health and nonprofit client data rarely exists in isolation. A single email address or phone number allegedly taken from CODAC’s files can be correlated with gaming usernames, social-media handles, and family-member records to build a complete identity chain. Once attackers link your treatment history to an online gamer tag or a child’s Roblox or Fortnite account, they gain leverage for extortion that feels intensely personal. Credential leaks of this nature frequently cascade into account takeovers across unrelated services, turning one breach into a multiplying set of compromises that expose your entire household.