On October 15, 2025, the Richmond Behavioral Health Authority appeared on the leak site of the qilin ransomware group after its internal files were allegedly exfiltrated during a ransomware attack. The Virginia-based organization provides mental health, substance abuse, and prevention services to residents of the City of Richmond and surrounding areas. Anyone who has received care there, or whose family member has, may have personal information now in the hands of criminals.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.
What Public Reporting Shows
Public reporting indicates that qilin listed RBHA on its data-leak portal and claimed to have stolen internal files. The exact number of individuals affected remains unknown. Available reporting describes the exposed material as internal documents rather than a structured database of patient records, though the precise contents have not been independently verified by third parties. The listing appeared on October 15, 2025, and follows the group’s standard pattern of publishing samples and demanding payment to prevent full release.
Why This Matters for You and Your Family
Mental health records, appointment details, insurance information, and contact data are among the categories that can appear in files maintained by behavioral health providers. When such information reaches ransomware operators, it can be sold, published, or used to launch further attacks against you. For many families, these records contain highly sensitive details about children, spouses, or elderly parents. Once the data leaves the provider’s control, you lose the ability to limit who sees it. The breach therefore shifts the burden of protection onto every person whose information may have been stored at RBHA.
The Doxxing and Identity-Chain Risk
Ransomware groups rarely stop at the first leak. They often comb through stolen files for email addresses, phone numbers, usernames, and references to family members. These fragments can be combined with data from earlier breaches to build a complete identity chain. A seemingly harmless note in a patient file can link an email address to a child’s gaming handle or a spouse’s social-media account. That linkage turns a single breach into repeated targeting: phishing texts, fraudulent loan applications, or public doxxing. Credential leaks of this kind frequently cascade into account takeovers precisely because the same password or recovery details appear across work, personal, and gaming services.