On January 19, 2026, the German social care organisation Wohnverbund St. Gertrud appeared on the leak site of the safepay ransomware group. The organisation, based in Morsbach, North Rhine-Westphalia, provides residential support and social care services. Public reporting indicates that internal files were exfiltrated during a ransomware attack, although the exact number of people affected remains unknown.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 582 companies.
See what is exposed about you — free scan →Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.
Reported Details of the Breach
Available reporting describes the incident as a ransomware attack in which safepay operators gained access to Wohnverbund St. Gertrud’s systems and removed internal documents before encrypting data. The organisation’s website, wohnverbund-st-gertrud.de, was listed on the group’s leak portal on 19 January 2026. No specific count of records or individuals has been published. The exposed material consists of internal files rather than a structured database of customer records, but such documents frequently contain names, addresses, dates of birth, care plans, financial details and correspondence.
Why This Matters for You and Your Family
When a care provider that holds sensitive personal information is breached, the consequences reach far beyond the organisation itself. If your family has ever received support from Wohnverbund St. Gertrud or a similar social care service, your private details may now sit in an attacker’s archive. Names, addresses and care records can be combined with data from earlier breaches to build a complete picture of your household. Criminals use this information for identity theft, targeted phishing, or selling it on underground markets. For families with children or vulnerable adults, the stakes are higher because medical or support details can be exploited to harass or impersonate.
The Doxxing and Identity-Chain Risk
Internal files from care organisations often link real names and addresses to email accounts, phone numbers and sometimes usernames used on other platforms. Once attackers possess these connections they can follow the chain into gaming accounts, social media and family cloud storage. A credential leak of this kind frequently cascades into account takeovers, especially for children’s gaming profiles that reuse passwords or security questions based on family information. The result is doxxing: personal addresses published online, harassment campaigns, or demands for payment to prevent further exposure.