On February 1, 2026, the Genesis Ransomware Group listed an unnamed non-profit organization on its leak site, claiming that internal files had been exfiltrated during a ransomware attack. The incident affects anyone whose personal information, donor records, employee details, or other sensitive documents were stored in the organization’s systems, potentially exposing you or members of your family to identity theft, harassment, or financial fraud.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch *****
Get alerted the next time ***** files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about *****’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting on the Genesis leak site, tracked by ransomware.live, shows the non-profit was added on February 1, 2026. The group claims to have stolen internal files but has not yet published a full data sample or detailed the exact volume of information taken. The victim count remains unknown, and the specific types of records exposed have not been independently verified beyond the group’s assertion of internal files exfiltrated. No evidence has surfaced that payment was made or that the data has been distributed beyond the leak site itself.
Why This Matters for You and Your Family
When a non-profit you support or work with suffers a breach, your personal data can end up in the hands of criminals. Internal files often contain names, addresses, phone numbers, email accounts, donation histories, and sometimes Social Security numbers or dates of birth. Once that information reaches dark-web markets, it can be used to open fraudulent accounts, file fake tax returns in your name, or target your family with phishing emails that look legitimate because they reference real past interactions. Children’s records held by the organization can also be exposed, increasing risks of identity fraud that may go undetected for years.
The Doxxing and Identity-Chain Implications
Stolen internal files frequently link usernames, email addresses, phone numbers, and real-world identities. Attackers can follow these connections across social media, gaming platforms, and other online services to build a complete profile. A single leaked email can lead to account takeovers on services where the same password was reused, exposing photos, messages, and location data. This chaining effect turns one breach into long-term surveillance and harassment risks for you and your family. Credential leaks like this one regularly cascade into gaming account takeovers, especially for children’s accounts that share household information.