On June 26, 2025, the First Presbyterian Church of Atlanta appeared on the leak site of the ransomware group known as Incransom. The church, which serves hundreds of families through children’s ministries, youth programs, and community outreach, is claimed to have had internal files exfiltrated after a ransomware attack. While the exact number of individuals whose personal information was taken remains unknown, the breach affects anyone whose records were stored in the church’s systems.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch firstpresatl.org
Get alerted the next time firstpresatl.org files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about firstpresatl.org’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Reported Details of the Breach
Public reporting indicates that Incransom added First Presbyterian Church of Atlanta to its disclosure page on June 26, 2025. The group claims to have stolen internal files during a ransomware incident. The church employs 86 people and operates with roughly $5 million in annual revenue. No specific count of affected records has been released, and the precise data types remain unclear beyond the broad description of internal files. The church has not yet issued a public statement confirming the incident or detailing what information may have been exposed.
Why This Matters for You and Your Family
Churches, schools, and community organizations routinely hold sensitive details about ordinary families: addresses, phone numbers, dates of birth, children’s names, emergency contacts, and sometimes financial pledges or donation records. When these organizations are breached, the information can appear on dark-web leak sites where criminals freely download it. If your family attends or has ever attended First Presbyterian Church of Atlanta, or if you have volunteered there, your data may now be in the hands of threat actors. Even a single exposed email or phone number can serve as the starting point for identity theft, phishing campaigns, or harassment aimed at you or your children.
The Doxxing and Identity-Chain Risks
Credential leaks and internal files from organizations like churches often contain enough personal details to link online handles, email addresses, and phone numbers to real-world identities. Once attackers establish these connections, they can pivot to gaming accounts, social-media profiles, and family devices. Children’s gaming accounts are especially vulnerable because kids frequently reuse passwords or email addresses tied to family church records. A breach like this can cascade into full doxxing chains that expose home addresses, family relationships, and daily routines. Available reporting describes how such chains frequently lead to account takeovers, swatting, or extortion attempts months after the initial leak.