On October 23, 2024, Easterseals appeared on the leak site operated by the rhysida ransomware group. The nonprofit organization, which provides disability and community services across the United States, was listed after attackers claimed to have exfiltrated internal files during a ransomware incident. The listing does not specify how many individuals may be affected or exactly which records were taken.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Easterseals
Get alerted the next time Easterseals files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Easterseals’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Details from the Leak Site
The rhysida leak site states that Easterseals suffered a ransomware attack in which internal files were successfully exfiltrated. No sample data has been published publicly on the site, and the listing does not quantify the volume or types of files involved. The disclosure indicates the organization was given a deadline to negotiate before further data would be released. As of the listing date, the exact nature of the internal files remains unknown to the public. Ransomware.live mirrors the original rhysida page, claiming the authenticity of the posting.
Why This Matters for You and Your Family
When a nonprofit like Easterseals is breached, the people who rely on its services often have the most to lose. Families who have sought support for children or adults with disabilities may have shared addresses, dates of birth, Social Security numbers, medical histories, or financial details. Even if the precise records taken are not yet known, the exposure of internal files creates a realistic risk that sensitive personal information tied to you or your loved ones could surface later. Once data leaves an organization’s control, it can be sold quietly on underground forums long before it appears in any public leak.
The Doxxing and Identity-Chain Risk
Internal files from service organizations frequently contain more than names and addresses. They can link email accounts, phone numbers, caregiver relationships, and sometimes children’s records. Attackers and data brokers routinely chain these fragments together. A single exposed email can lead to an associated gaming username; that username can reveal a child’s real name and location when combined with other leaked details. The result is a complete identity profile that enables harassment, targeted phishing, or account takeovers across services. Credential leaks of this kind often cascade into gaming account compromises because the same passwords or recovery emails are reused. Children’s gaming accounts become especially vulnerable when household data is exposed.