On October 14, 2025, the European Organisation for Rare Diseases, known as EURORDIS, appeared on the leak site of the qilin ransomware group. The organization, which supports millions of people across Europe living with rare diseases, is claimed to have had internal files exfiltrated during a ransomware attack. While the exact number of individuals whose information may be exposed remains unknown, anyone who has interacted with EURORDIS — whether as a patient, family member, donor, employee, or partner — could be affected.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Eurordis
Get alerted the next time Eurordis files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Eurordis’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting indicates that qilin posted EURORDIS to its leak site on October 14, 2025. The data consists of internal files exfiltrated following a ransomware deployment. No specific volume of records or detailed list of data types has been publicly confirmed beyond the broad category of internal documents. The organization itself has not yet issued a public statement detailing the breach scope or timeline of initial compromise.
Why This Matters for You and Your Family
If you or someone in your family has ever shared personal health details, contact information, or financial data with EURORDIS, those details may now sit in a ransomware leak. Health-related records are especially sensitive because they can reveal diagnoses, treatment histories, and family medical patterns. Criminals routinely use such information for identity theft, insurance fraud, or targeted scams that feel deeply personal. Even if your name is not on the main patient list, a single shared email, phone number, or address can link you to the breach.
The Doxxing and Identity-Chain Risks
Stolen internal files often contain more than obvious personal data. They can include staff directories, partner lists, donor spreadsheets, email correspondence, and login credentials. Once these appear on a ransomware site, other criminals scrape them and begin building identity chains — linking an email from one breach to a username in another, then to a child’s gaming account or a family member’s social profile. Credential leaks like this one cascade into account takeovers that feel unrelated until it is too late. Gaming accounts belonging to you or your children are frequent targets because they often reuse the same passwords or recovery emails exposed in professional breaches.