On May 24, 2025, the Salvation Army appeared on the leak site of the interlock ransomware group in a listing claiming internal files were exfiltrated during a ransomware attack. The organization, founded in 1865, provides food assistance, disaster relief, shelter, clothing, and support programs for children, the elderly, the disabled, and the homeless. While the exact number of individuals whose information may have been exposed remains unknown, anyone who has interacted with the Salvation Army—through donations, volunteering, job applications, or receiving services—may have records included in the stolen data.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch The Salvation Army
Get alerted the next time The Salvation Army files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about The Salvation Army’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Available reporting describes the incident as a ransomware attack in which interlock gained access to the Salvation Army’s systems, exfiltrated files, and later listed the organization on its public leak site. The data exposed consists of internal files; specific categories mentioned in public posts include documents that could contain donor records, employee information, client case files, and operational details. No confirmed count of affected records has been released. The Salvation Army has not yet issued a detailed public statement on the volume or sensitivity of the stolen information.
Why This Matters for You and Your Family
When a large charity like the Salvation Army suffers a breach, ordinary people are often the ones at risk. You or your family may have provided personal details when seeking emergency help, applying for assistance programs, donating goods, or signing children up for youth activities. Internal files frequently hold names, addresses, phone numbers, dates of birth, Social Security numbers, banking information for recurring donors, and email addresses. Once this information leaves secure systems, it can be sold, traded, or used to target you with identity theft, phishing, or financial fraud. Children’s records held by charitable organizations are especially concerning because they can be paired with gaming usernames or school details later.
The Doxxing and Identity-Chain Implications
Ransomware leaks rarely stop at one organization. A single exposed email or phone number can be cross-referenced with data from previous breaches, creating an identity chain that links your online handles, family members’ accounts, and real-world identity. Public reporting indicates that attackers and data brokers routinely combine leaked charity records with information from retail breaches, streaming services, and gaming platforms. This chaining process turns a single incident into long-term exposure. Credential leaks like this one often cascade into account takeovers on gaming platforms, where children’s usernames and passwords are reused, opening the door to harassment, doxxing, and further extortion.