On August 3, 2023, the Roman Catholic Diocese of Albany appeared on the leak site operated by the nokoyawa ransomware group. The listing states that internal files were exfiltrated during a ransomware attack on the diocese, which serves 14 counties in eastern New York plus a portion of a fifteenth. The notification does not disclose the number of people affected or specify which exact records were taken.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Roman Catholic Diocese of Albany
Get alerted the next time Roman Catholic Diocese of Albany files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Roman Catholic Diocese of Albany’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Details from the Leak Site
The primary disclosure on the nokoyawa onion site lists the Diocese of Albany and claims successful data exfiltration. It does not quantify the volume of stolen material or name the specific systems compromised. Public mirrors of the leak site, such as ransomware.live, state the posting date as August 3, 2023. The group typically posts samples or announcements after encryption to pressure victims into payment; in this case the listing indicates that internal files were taken but does not detail their contents.
Internal files exfiltrated is the only description provided. No sample documents have been publicly indexed by mainstream breach repositories at the time of this analysis.
Why This Matters for You and Your Family
Even when a breach targets a religious institution rather than a commercial database, the people whose information lives in those internal files face real risk. If you, your spouse, or your children were baptized, confirmed, married, or received other sacraments through a parish in the Diocese of Albany, your names, addresses, dates of birth, and possibly Social Security numbers or financial details used for donations may have been stored in the compromised systems. Parishes often maintain family records spanning decades; a single leak can therefore expose multiple generations.