On January 27, 2025, the International AIDS Vaccine Initiative appeared on the leak site of the incransom ransomware group. The organization, a nonprofit that develops HIV vaccines and supports related research, is claimed to have had internal files exfiltrated during a ransomware attack. While the exact number of people whose information may have been exposed remains unknown, anyone whose personal, financial, or health-related records were stored in IAVI systems could be affected.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch International AIDS Vaccine Initiative
Get alerted the next time International AIDS Vaccine Initiative files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about International AIDS Vaccine Initiative’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Reported Details of the Breach
Public reporting indicates that incransom added IAVI to its leak site and published proof of the exfiltration. The data consists of internal files taken during the ransomware incident. No confirmed total of records or specific victim count has been released. The listing appeared on the group’s .onion blog, which serves as its primary disclosure platform. Available reporting describes the incident as a standard ransomware operation involving both encryption and data theft for extortion.
Why This Matters for You and Your Family
When a research organization like IAVI suffers a breach, the exposed internal files can contain names, contact details, dates of birth, financial information, or even medical data tied to clinical trials or partnerships. If your information or that of a family member was included, it can be sold or published, increasing the risk of identity theft, phishing, or targeted scams. Health-related nonprofits often hold sensitive records that feel especially personal. One breach can quietly link your details to other accounts you use every day, putting your household at risk long after the initial incident fades from the news.
The Doxxing and Identity-Chain Risks
Ransomware leaks rarely stop at one dataset. Criminals frequently cross-reference stolen information with other breaches to build detailed profiles. A work email from an IAVI file can be matched to a personal account, a phone number, or a child’s gaming username. These connections create doxxing chains that lead to harassment, account takeovers, or extortion. Credential leaks of this kind often cascade into gaming platforms, where children’s accounts become entry points for further targeting because the same passwords or recovery emails are reused. Once the chain begins, stopping it requires more than simply changing one password.