On May 9, 2025, Habitat for Humanity of Greater Sioux Falls appeared on the leak site of the qilin ransomware group. The nonprofit, which helps families in the Minnehaha County area obtain affordable housing, may have had internal files stolen during a ransomware attack. While the exact number of people whose information was taken remains unknown, any donor, volunteer, employee, or program participant who provided personal details could be affected.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Habitat for Humanity of Greater Sioux
Get alerted the next time Habitat for Humanity of Greater Sioux files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Habitat for Humanity of Greater Sioux’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting indicates that qilin actors exfiltrated internal files from the organization’s systems before encrypting them. The data includes documents that typically contain names, addresses, contact information, financial details tied to donations or program applications, and other records used in daily operations. No precise count of exposed records has been released, and the organization has not yet issued a public statement detailing the scope. The listing on the qilin leak site carries a deadline for payment or further data publication, a standard pressure tactic used by the group.
Why This Matters for You and Your Family
When a local nonprofit like Habitat for Humanity suffers a breach, the impact reaches ordinary families who trusted the organization with sensitive information. Addresses, phone numbers, email accounts, and financial records can be sold or published, increasing the risk of identity theft, targeted phishing, or unwanted solicitations. If you or your family have ever applied for housing assistance, volunteered, or made a donation, your information may now sit in an attacker’s database. Children’s names or school-related details sometimes appear in nonprofit files as well, creating long-term exposure that parents must address.
The Doxxing and Identity-Chain Implications
Stolen internal files rarely stay isolated. Attackers combine them with data from earlier breaches to build detailed profiles. A single address or email can link gaming usernames, social-media handles, and family relationships, turning one leak into a chain of doxxing risks. Credential leaks like this one often cascade into account takeovers on gaming platforms, where children’s accounts become entry points for further harassment or extortion. Public reporting shows these chains frequently lead to swatting attempts, identity fraud, or relentless spam directed at home addresses that were meant to stay private.