Skip to content
Back to Blog
medium severity September 08, 2026 · 3 min read Unverified claim — what this is

Recovery Cafe Listed by Safepay Ransomware

If you were named in this filing, here’s what is being claimed, and what it would mean for you.

Safepay ransomware group published recoverycafe.org as a victim. The Seattle-based nonprofit operates community cafes supporting recovery from addiction and homelessness. This is the earliest public listing; no organizational notification found.

— from SafePay’s own leak-site posting. This is the group’s claim, quoted verbatim; it is not GalaxyWarden’s reporting and has not been independently verified.
Recovery Cafe Listed by Safepay Ransomware

The Safepay ransomware group has listed Recovery Cafe on its leak site, claiming the Seattle nonprofit is a victim. The organisation has not publicly confirmed the claim as of this writing. No details about the number of people affected or the specific data involved have been disclosed by Recovery Cafe itself.

Watch Recovery Cafe

Get alerted the next time Recovery Cafe files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.

We’ll email you only about Recovery Cafe’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.

Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals — $499/mo or $4,990/yr.

Your Records May Now Be Publicly Marketed for Extortion

Your Records May Now Be Publicly Marketed for Extortion

If the group’s claim is accurate, information you entrusted to Recovery Cafe could be sitting on a ransomware leak site right now. That changes the risk profile of anything you ever provided them. Because no passwords were part of the exposed data, this is not a credential breach. Your Recovery Cafe account itself is not at immediate risk of takeover. What matters instead are the permanent or semi-permanent identifiers that do not reset like a password can.

Non-profits like Recovery Cafe routinely hold names, contact details, dates of birth, government identifiers, and sometimes financial or health-related information tied to donations, program enrollment, or support services. If any of those categories were taken, they cannot be cancelled or reissued the way a compromised credit card can. The exposure, if real, is permanent in its usefulness to identity thieves, fraudsters, and people running phishing or imposter scams.

What a Ransomware Leak-Site Listing Actually Establishes

What a Ransomware Leak-Site Listing Actually Establishes

A listing on a ransomware extortion site is an accusation, not evidence. These groups frequently post organisations after failed negotiations, sometimes with recycled or overstated data, and occasionally with targets they never actually compromised. The publication serves as leverage to pressure the victim into paying. It does not come with independent verification, forensic reports, or confirmation from the named organisation.

Real confirmation would require a statement from Recovery Cafe, a regulatory filing, or notification letters sent directly to affected individuals. Until that happens, the safest stance is cautious skepticism. Many such listings later prove exaggerated, old, or entirely false. At the same time, the mere appearance on these sites creates immediate risk because opportunistic criminals will still attempt to use any information that might have been obtained, whether the claim is fully accurate or not.

The Pattern Seen Across Small Non-Profits and Charities

Ransomware crews often treat smaller charities, community organisations, and non-profits as low-effort targets in a “spray and pray” model. They cast a wide net, demand modest ransoms relative to larger corporations, and use public shaming on leak sites as cheap pressure. The organisations hit are frequently those with limited security staff and budgets, making them attractive for quick wins. This pattern does not prove Recovery Cafe was breached, but it explains why such groups appear on these lists with surprising frequency.

For you, the practical takeaway is that non-profits you interact with for support, donations, or services can become vectors for your information ending up in the wild. The next time you see a similar listing, the same conditional logic applies: treat the claim seriously enough to check for notification, but do not assume it is proven until the organisation says so directly.

What You Can Still Control

Even when identifiers are exposed, you retain power over how that information is used against you. The key is early detection and rapid response to any attempt to open new accounts, file fraudulent taxes, or impersonate you with government agencies.

Place a freeze with all three major credit bureaus so new credit cannot be opened in your name without your explicit permission. Monitor your credit reports regularly for unfamiliar inquiries or accounts. Set up alerts with the IRS and your state tax authority to block fraudulent filings. If you receive unexpected calls, texts, or emails that appear to come from Recovery Cafe or related services, treat them as suspicious until verified through official channels.

Because the filing does not state when any alleged incident occurred, there is no reliable date to anchor a “have you moved” test. The only practical way to determine whether your specific records were involved is to receive direct notification from Recovery Cafe. If you have not received such a letter, it usually means you were not in the affected group, but anyone who has changed address since first interacting with the organisation should contact them directly to confirm their status.

GalaxyWarden provides continuous monitoring across 13.1 billion breach records and more than 100 platforms, with identity-chain mapping and remediation handled by specialists.

What the free scan actually returns

Sample resultyou@email.comIllustrative — not a real person

Found on people-search siteswe remove these

These listings are live, public, and legal to remove — and removing them is what we do.

value redacted in this sampleage, relatives, address historySpokeo
value redacted in this samplephone, household, property recordsBeenVerified
value redacted in this sample580 companies checked

Found in breach recordsverifiedreported — unverified

Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.

verifiedvalue redacted in this samplepassword + phone · 2024telecom breach
unverifiedvalue redacted in this sampleclaimed in ransomware listing · 2026leak-site claim

Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.

Check your exposure
Recovery Cafe is one listing. Your email is probably in others.
We can’t confirm any single incident against the sources we search, so we won’t pretend to. What we can show you is your own exposure — your email against 13.1B+ leaked records and the sites that publish your address. About 15 seconds. No account, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Report details & sourcing

Severity Medium contact details only, none of them permanent
Disclosed September 08, 2026
Last reviewed September 8, 2026
Affected Unconfirmed
Data exposed unknown
Unverified claim — what this report is
This page documents a public listing on a ransomware/extortion group’s leak site, tracked via public threat-intelligence sources. A listing is the attacker’s claim. GalaxyWarden aggregates and reports such claims; we have not independently verified that a breach occurred, what data (if any) was taken, or the accuracy of anything the group asserts, and the named organisation has not necessarily confirmed the incident. Sections above describe what the listing shows and the group’s documented history — not verified findings about the named organisation. If you represent this organisation and believe anything here is inaccurate, tell us and we’ll review it promptly.
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Sources: ransomlook.io
Share this Post on X Reddit Email