On June 4, 2024, the Women's Sports Foundation appeared on the Medusa ransomware group's leak site. The organization, which supports girls and women in sports through programs, research, and funding, had 36.5 GB of internal files exfiltrated. The Medusa listing does not specify the exact number of people affected or list the precise data types exposed beyond claiming that sensitive internal documents were taken.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Women's Sports Foundation
Get alerted the next time Women's Sports Foundation files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Women's Sports Foundation’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Details from the Medusa Listing
The primary disclosure on the Medusa leak site states that the Women's Sports Foundation suffered a ransomware attack resulting in the theft of internal files. The entry, accessible via the onion link hosted on ransomware.live, shows 36.5 GB of data and gives the foundation until a set deadline to negotiate before the files are fully published. No sample data is currently displayed, and the listing does not quantify how many employee, donor, or program participant records may be included. The attack targeted the foundation's corporate systems at its New York City office, though the precise initial access vector remains undisclosed by either party.
Why This Matters for You and Your Family
When a nonprofit like the Women's Sports Foundation is breached, the people whose information ends up in the stolen files face direct risk. If you or your daughters have participated in any of their programs, received grants, attended events, or donated, your contact details, financial information, or personal identifiers could be among the 36.5 GB now held by criminals. Even without exact record counts, the exposure of internal files typically includes spreadsheets, emails, contracts, and databases that map real people to addresses, phone numbers, dates of birth, and payment records. For families involved in youth sports, this creates a tangible privacy threat that can follow children into adulthood.
Doxxing and Identity-Chain Risks
Stolen internal files rarely stay isolated. Attackers and subsequent buyers combine them with other breaches to build detailed identity chains linking names, emails, phones, social media handles, and family relationships. A donor record from the Women's Sports Foundation can be cross-referenced with a child's sports registration or a parent's social-media account, rapidly escalating from simple data exposure to full doxxing. Public reporting on similar incidents shows these chains frequently lead to targeted phishing, account takeovers, and harassment. Credential leaks that surface in these datasets also cascade into gaming platforms, where children's accounts become entry points for further compromise of the entire household.