On March 3, 2026, the German nonprofit Franz-Sales-Haus.de appeared on the leak site of the safepay ransomware group after its internal files were allegedly exfiltrated during a ransomware attack. The organization, based at Steeler Straße 261, 45138 Essen, provides support services that help people with disabilities live independently. While the exact number of individuals whose information may have been exposed remains unknown, any personal records held by the nonprofit may now be in the hands of attackers.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Franz-Sales-Haus.de
Get alerted the next time Franz-Sales-Haus.de files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Franz-Sales-Haus.de’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting indicates that safepay posted details of the Franz-Sales-Haus breach on its dark-web leak site. The data consists of internal files exfiltrated following a ransomware deployment. No confirmed total of affected records has been released, and the precise contents of the leaked files have not been independently verified by third parties. The incident follows the group’s typical pattern of publishing victim data when ransom demands are not met.
Why This Matters for You and Your Family
When a support organization that assists vulnerable people suffers a breach, the ripple effects can reach the very families it serves. Personal details submitted during intake, case notes, contact information, or even financial records used for service coordination could be exposed. For you or your family, that might mean increased risk of identity theft, targeted scams, or unwanted contact from people who should never have had that information. Even a single leaked address or phone number tied to a disability-support file can make everyday privacy harder to maintain.
The Doxxing and Identity-Chain Implications
Ransomware leaks like this one rarely stop at the first dataset. Attackers or opportunistic criminals often combine the newly exposed internal files with information already circulating on forums and breach repositories. A seemingly harmless support-organization record can link an email address to a real name, physical address, and family relationships. Once those connections exist, doxxing chains form quickly: gaming usernames, children’s accounts, social-media handles, and phone numbers all become easier to tie together. Credential leaks of this nature frequently cascade into account takeovers across unrelated services.