On February 21, 2024, Country Villa Service Corp., operating as Country Villa Health Services, appeared on the LockBit 3.0 ransomware leak site. The listing states that internal files were exfiltrated during a ransomware attack on the California-based operator of roughly 50 skilled nursing and assisted living facilities. The disclosure does not quantify how many patient or employee records were affected, nor does it list specific data types beyond the broad description of internal files.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.
Details from the Leak Site
The LockBit 3.0 panel entry states that Country Villa Health Services data was stolen and is now published after the company did not meet the group's payment deadline. The primary source, hosted on the LockBit onion site and mirrored on ransomware.live, shows sample files but does not detail the volume or exact contents. Public reporting on LockBit operations indicates that when exact record counts are omitted it usually means the actor is still attempting to pressure the victim through selective leaks rather than full disclosure. The notification leaves open the possibility that sensitive health records, employee payroll data, or resident personal information may be included among the exfiltrated material.
Why This Matters for You and Your Family
If you or a loved one has received care at any Country Villa facility in California, particularly the roughly 25 centers located in Los Angeles County, your personal and medical information could be exposed. Health-related records carry lifelong consequences because they combine names, dates of birth, Social Security numbers, insurance details, and clinical histories in one package. Criminals can use this information to file fraudulent tax returns, open accounts in your name, or impersonate you during medical visits. Families with elderly relatives in assisted living are especially vulnerable because seniors often share addresses and phone numbers with adult children, creating a single point of failure that can expose multiple generations at once.
Doxxing and Identity-Chain Risks
A single health-care breach rarely stops at the initial leak. Threat actors and downstream buyers chain the stolen data with usernames, emails, and phone numbers harvested from other sources to build complete identity profiles. Once your name and date of birth from a nursing-home record are linked to a gaming username or family email address, attackers can hijack accounts, demand ransom from relatives, or sell the package on dark-web marketplaces. Credential leaks of this nature frequently cascade into gaming account takeovers, especially for children or grandchildren who reuse passwords or security questions derived from family information. The speed at which these chains form leaves most victims unaware until fraudulent charges or impersonation attempts surface months later.