On December 1, 2025, the Easterseals Northeast Iowa website www.eastersealsnei.org appeared on the leak site of the devman ransomware group. The attackers claim to have exfiltrated 280 GB of internal files and are demanding a $550,000 ransom. While the exact number of people whose personal information is contained in the files remains unknown, any organization serving families, children, and people with disabilities routinely holds sensitive records that, once exposed, directly affect the privacy of the individuals and households it supports.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 582 companies.
See what is exposed about you — free scan →Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.
What's Publicly Reported from Reporting
Public reporting on the devman leak site, tracked by ransomware.live, lists Easterseals Northeast Iowa as a victim. The posting states that 280 GB of internal files were taken during a ransomware incident. No sample data has been publicly released at the time of this writing, and the precise contents have not been independently verified. The group has set a $550,000 payment deadline, after which it threatens to publish or sell the stolen material. Easterseals Northeast Iowa is a nonprofit that provides services to children and adults with disabilities across northeast Iowa, meaning the files could include donor records, client information, employee data, or internal operational documents.
Why This Matters for You and Your Family
When a nonprofit like Easterseals has its internal systems breached, the ripple effects reach the families it serves. Medical or therapy notes, contact details, Social Security numbers, insurance information, or family addresses may be inside the 280 GB archive. Once that data leaves the organization’s control, it can be used for identity theft, targeted scams, or sold on underground markets. Even if your name is not on the front page of the leak, any connection to the organization—whether as a client, donor, employee, or vendor—puts your household at higher risk. Criminals do not need every record to cause harm; a single reused email address or phone number is often enough to begin an attack chain that eventually reaches you and your family.
The Doxxing and Identity-Chain Implications
Ransomware leaks rarely stop at one organization. The exposed files can contain email addresses, usernames, or internal spreadsheets that link real identities to other online accounts. These connections allow attackers to follow an identity chain: an email from the Easterseals breach might match a credential found in an earlier gaming-site leak, which then leads to a family member’s social-media profile or a child’s gaming account. Public reporting indicates that such credential leaks frequently cascade into account takeovers and doxxing campaigns. When children’s information or linked gaming accounts are involved, the exposure can lead to harassment, swatting, or further extortion. The longer these links remain unmapped, the more damage can accumulate before you even realize the original breach occurred.