Grace Lutheran Foundation Inc. was listed on the Alphv ransomware leak site on January 22, 2024, after the group claimed to have exfiltrated more than 70GB of internal files from the senior-care organization. The disclosure states that negotiations failed and the data is now being published because the foundation refused to protect the information of its employees and patients.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Grace Lutheran Foundation
Get alerted the next time Grace Lutheran Foundation files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Grace Lutheran Foundation’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Details in the Leak-Site Listing
The Alphv post explicitly names Grace Lutheran Communities and describes a ransomware attack that resulted in the theft of internal files. The listing does not quantify the number of affected individuals, nor does it itemize every record type exposed. It states that over 70GB of data was taken and that the files are now being shared publicly after weeks of unsuccessful negotiations. The primary disclosure makes clear the organization offers independent apartments, assisted living, memory care, skilled nursing, and other senior services, meaning the stolen material likely touches both employee records and resident or patient information.
Why This Matters for You and Your Family
When a senior-care provider is breached, the people most directly exposed are often older adults, their adult children coordinating care, and current or former employees. If you or a family member has lived at, worked at, or received services from Grace Lutheran Foundation or its affiliated communities, your personal details may now sit in an attacker-controlled archive. The disclosure indicates that patient and customer data were part of the stolen material, raising the possibility of medical histories, insurance numbers, Social Security details, and contact information entering criminal ecosystems. Even without an exact victim count, the volume—more than 70GB—suggests thousands of records could be involved.
Doxxing and Identity-Chain Risks
Stolen internal files rarely contain only one data point. A single spreadsheet can link a resident’s name, date of birth, address, phone number, and next-of-kin contacts. Attackers routinely combine these fragments with credential leaks from other breaches to build persistent identity chains. Once an email and password pair surfaces, it can be tested against banking, government, and retail sites. For families, the risk extends to adult children listed as emergency contacts or financial guarantors. Children’s gaming accounts that reuse the same passwords or security questions also become gateways; a compromised Roblox or Minecraft credential can lead to further personal details being extracted and sold. Continuous monitoring across large breach repositories is one of the few practical ways to catch these cascading exposures before they escalate into full identity theft or targeted harassment.