On December 26, 2025, the LGBTQ Center Orange County appeared on the leak site of the ransomware group IncRansom, which stated it had exfiltrated internal files and planned to publish them the following week.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.
What Public Reporting Shows
Public reporting indicates the LGBTQ Center OC, a nonprofit founded in 1971 and incorporated in 1975, serves more than 20,000 people each year. The organization provides support across diverse cultural, ethnic, age, and economic backgrounds in Southern California. Available reporting describes the incident as a ransomware attack in which internal files were taken. The group set a public deadline to release the data in early January 2026. No confirmed victim count for individuals has been released, and the precise volume or sensitivity of the files remains unclear from current public posts on the IncRansom leak site.
Why This Matters for You and Your Family
When a community organization that holds personal information suffers a breach, the people it serves can face unexpected risks. If you or your family have ever used its counseling services, attended events, volunteered, or appeared in donor lists, your names, contact details, or other records may now sit in an attacker’s hands. Internal files often contain more than basic contact information; they can include notes, correspondence, or details that feel private. Once that material reaches the public internet, it becomes difficult to remove and easy for others to copy. Ordinary families who trusted the center with sensitive personal matters now need to treat this incident as seriously as any large corporate breach.
The Doxxing and Identity-Chain Implications
Ransomware leaks rarely stop at one database. Attackers or opportunistic criminals frequently cross-reference newly exposed emails, usernames, or phone numbers against information already circulating on forums and breach repositories. This creates an identity chain that can link your gaming handle, social-media accounts, and real-world identity. Credential leaks of this kind often cascade into account takeovers, especially for gaming platforms where children’s accounts may reuse the same email or password. Once a doxxing chain begins, harassers can locate home addresses, family member names, and other details that make everyday life feel unsafe. The risk is not abstract; it is a direct path from one compromised nonprofit file to repeated targeting across the internet.