On August 15, 2024, Liberty Resources, Inc., a Syracuse, New York-based human services agency, appeared on the leak site operated by the rhysida ransomware group. The listing states that internal files were exfiltrated during a ransomware attack. The organization has not yet published a formal breach notification detailing the exact records involved or the number of people affected.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Liberty Resources
Get alerted the next time Liberty Resources files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Liberty Resources’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Details from the Leak Site
The rhysida leak site entry states that Liberty Resources was hit by a ransomware operation and that attackers successfully removed internal files. No specific volume of data or list of exposed record types is provided in the posting. The disclosure indicates the incident falls under the group’s double-extortion model, in which stolen data is held for ransom and later published if payment is not made. As of the listing date, the sample files or full archive had not been released to the public, and the exact deadline given to the victim remains unknown.
Why This Matters for You and Your Family
When a community-facing nonprofit like Liberty Resources suffers a breach, the people most likely to be exposed are those who have received services, applied for assistance, or had family members in its programs. Internal files often contain names, addresses, dates of birth, Social Security numbers, medical or disability details, and financial assistance records. Even without an exact count, any family in Central New York that interacted with the agency in the past several years should treat their information as at risk. Once such data leaves controlled systems, it can surface on dark-web markets for years, increasing the chance of identity theft, tax fraud, or targeted scams against you or your children.
Doxxing and Identity-Chain Risks
Stolen internal files rarely stay isolated. Attackers and subsequent buyers combine them with other leaks to build detailed profiles. An email address from this incident can be linked to your gaming username, social-media handles, or children’s school accounts. That linkage turns a single breach into a doxxing chain: one credential leak leads to account takeovers, which expose chat logs, location data, or family photographs. Gaming accounts belonging to teenagers are especially vulnerable because kids often reuse passwords across homework portals, Roblox, Fortnite, or Discord. The result is a map that points straight back to your household address and real identities.