On August 22, 2024, the Australian disability-support organisation Engedi appeared on the leak site operated by the Rhysida ransomware group. The listing states that internal files were exfiltrated during a ransomware attack on the Mackay-based community service provider. The disclosure does not specify the number of people affected or list the exact data types contained in the stolen material.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Engedi
Get alerted the next time Engedi files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Engedi’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Reported Details from the Listing
The Rhysida leak site entry states that Engedi suffered a ransomware incident and that attackers successfully removed internal files. No victim count is published, and the listing does not detail which systems were compromised or the volume of data taken. The organisation itself has not yet issued a public breach notification quantifying impact on clients, staff or donors. Public reporting on Rhysida indicates the group typically posts samples or full datasets when victims refuse to pay the demanded ransom.
Why This Matters for You and Your Family
If you or a family member have received support from Engedi, worked there, volunteered, or donated, your personal information may now sit in an attacker-controlled archive. Disability-service providers routinely hold names, addresses, dates of birth, medical or support details, government identifiers and contact records for vulnerable individuals. Once such data leaves the organisation’s control, it can be used for identity theft, phishing campaigns or sold on underground markets. Even when the leak site does not publish every record, the mere confirmation of exfiltration creates long-term exposure for every person whose details were stored in the affected systems.
Doxxing and Identity-Chain Risks
Stolen internal files frequently contain spreadsheets that link names to addresses, phone numbers, email accounts and sometimes family-member details. Attackers and subsequent buyers can combine this information with credential leaks from other breaches to build complete identity profiles. A single exposed email or phone number becomes the starting point for account takeover attempts across banks, government portals and social media. When children’s records or family-support notes are included, the exposure can extend to gaming accounts, school portals and online communities that reuse the same passwords or recovery details.