On August 27, 2025, the ransomware group known as worldleaks added Saint Mary's Home to its public leak site, claiming that internal files from the Norfolk, Virginia nonprofit had been exfiltrated. The organization provides specialized care for children and young adults with severe disabilities from birth to age 21, including medical records, therapy notes, family contact details, and administrative data that could affect hundreds of vulnerable families.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Saint Mary's Home
Get alerted the next time Saint Mary's Home files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Saint Mary's Home’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting indicates the incident stems from a ransomware attack in which attackers gained access to Saint Mary's Home systems, copied sensitive internal files, and later listed the organization on the worldleaks dark-web portal. The exact number of individuals affected remains unknown, but the data types exposed include personal information tied to children receiving care, their parents or guardians, staff members, and operational records. No evidence has surfaced that the files have been broadly distributed beyond the leak site, yet their presence on a ransomware portal means the information is now available to other threat actors.
August 27, 2025 marks the public confirmation date. The breach follows a pattern seen in prior ransomware cases where initial encryption is followed by data exfiltration and extortion pressure through public exposure.
Why This Matters for You and Your Family
When a children's care provider is breached, the fallout reaches far beyond the nonprofit. Families who trusted Saint Mary's Home with medical histories, therapy progress, contact information, and daily routines now face the possibility that those details sit on a criminal marketplace. For any parent whose child has received services there, this means potential identity theft, targeted scams, or even physical risks if addresses and health conditions become public.