On March 29, 2024, the Pennsylvania Southeast Conference of the United Church of Christ appeared on the leak site operated by the incransom ransomware group. The listing states that internal files were exfiltrated during a ransomware attack on the regional church body, which serves congregations across Philadelphia and its surrounding suburbs. Anyone connected to the conference—members, employees, donors, or vendors—may have personal information now in the hands of extortionists.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch PSEC Church
Get alerted the next time PSEC Church files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about PSEC Church’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Details from the Leak Site
The incransom leak page, first indexed on March 29, 2024, claims the group obtained internal files after deploying ransomware against the Pennsylvania Southeast Conference. The posting does not quantify how many records were taken, list specific data types beyond “internal files,” or name the exact systems compromised. It follows the group’s standard format: an initial access announcement, followed by samples and a countdown to full publication if demands are not met. No ransom amount is disclosed on the public page.
Why This Matters for You and Your Family
Church conference records routinely contain names, addresses, phone numbers, email addresses, dates of birth, Social Security numbers, banking details for donations or payroll, and pastoral counseling notes. When such data leaves a nonprofit’s control, the exposure is personal. Families who attend affiliated churches, staff who work at conference offices, or volunteers whose background checks were filed centrally now face heightened risk of identity theft, phishing, and financial fraud. The disclosure indicates the data was taken; it does not state whether it has already been sold or shared on other forums.
Doxxing and Identity-Chain Risks
Church directories, internal spreadsheets, and email archives often link personal emails to home addresses, spouse names, and children’s names. Attackers can chain this information with handles from social media or gaming accounts to build complete profiles. A single leaked pastor’s spreadsheet can expose dozens of households. DoxxScan by GalaxyWarden continuously monitors 13.1B+ breach records and 100+ platforms with AI-powered identity-chain mapping and hands-on remediation by specialists, including household coverage that extends to children’s gaming accounts vulnerable to the same credential cascades.