On December 5, 2025, the Center of Association Management appeared on the leak site of the nightspire ransomware group. Public reporting indicates the organization suffered a ransomware attack in which internal files were exfiltrated. While the exact number of people whose information may have been exposed remains unknown, anyone whose records passed through the Center’s systems — members, employees, vendors, or their families — may now face heightened risk of identity theft and doxxing.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch The Center of Association Management
Get alerted the next time The Center of Association Management files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about The Center of Association Management’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Reported Details of the Incident
Available reporting describes the incident as a classic ransomware operation. The attackers gained access to the Center’s network, encrypted systems, and exfiltrated internal files before publishing a sample on their leak portal. The data includes documents that could contain names, addresses, contact details, financial records, and other sensitive business information tied to the association-management clients the Center serves. No confirmed timeline of the initial breach has been released, but the listing on the nightspire leak site on December 5, 2025 marks the public disclosure phase.
The Center of Association Management provides administrative support to trade associations, professional societies, and nonprofit organizations. Its client base means the exposed files likely reference thousands of individual members and their families across multiple industries.
Why This Matters for You and Your Family
When an organization that handles membership records is breached, the impact reaches far beyond corporate walls. If you or anyone in your household belongs to an association, professional group, or nonprofit that uses the Center’s services, your personal information may have been inside the stolen files. Names, addresses, emails, and phone numbers are frequently sufficient for criminals to begin building a profile that leads to account takeovers, fraudulent loan applications, or targeted phishing.