On November 20, 2023, the nonprofit organization onyourmark.org appeared on the LockBit 3.0 ransomware leak site, claiming that internal files had been exfiltrated during a ransomware attack. The listing affects anyone whose personal information was stored in the organization’s systems, including individuals with intellectual and developmental disabilities, their families, staff members, and donors whose records may now sit in the hands of extortionists.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch onyourmark.org
Get alerted the next time onyourmark.org files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about onyourmark.org’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Reported Details from the Listing
The LockBit 3.0 leak page states that On Your Mark suffered a ransomware intrusion and that attackers successfully exfiltrated internal files. The disclosure does not quantify how many records were taken, list specific data types such as names, Social Security numbers, medical details, or financial information, or provide a ransom demand. It simply marks the organization as compromised and displays a countdown timer typical of the group’s extortion playbook. The primary source remains the onion link hosted on the LockBit infrastructure, mirrored publicly through ransomware.live at http://lockbitapt2d73krlbewgv27tquljgxr33xbwwsp6rkyieto7u4ncead.onion/post/EypQYeiYzry7ZOvr65590eb37e836.
Why This Matters for You and Your Family
When a community nonprofit that supports people with intellectual and developmental disabilities is breached, the exposure reaches far beyond the office walls. Families who rely on these services often share sensitive details about medical histories, guardianship arrangements, government benefit identifiers, and contact information. If those records were inside the stolen files, your family’s private information is now at risk of being sold or published. Even without an exact victim count, the high-severity ransomware listing signals that operational data containing personal identifiers was taken. For ordinary families already navigating complex care systems, this adds another layer of worry about identity theft, benefit fraud, or unwanted exposure of a loved one’s disability-related records.
The Doxxing and Identity-Chain Risks
Ransomware groups rarely stop at encrypting files. Once data leaves the victim’s network it enters underground markets where handles, emails, phone numbers, and partial personal records are stitched together into detailed profiles. A single leaked email from an On Your Mark intake form can link to your child’s school account, your spouse’s workplace login, or family addresses used across government assistance portals. These connections create doxxing chains that allow criminals to harass, impersonate, or target families for further scams. Credential leaks of this nature frequently cascade into gaming account takeovers, especially for children who share family email addresses or passwords. The longer the data sits on a leak site, the higher the chance that opportunistic actors will exploit these links.