On December 7, 2024, the non-profit League Education & Treatment Center in Brooklyn, New York, appeared on the RansomHub leak site. The organization, which supports children and adults with psychiatric and developmental disabilities including autism, had internal files exfiltrated during a ransomware attack. The exact number of people whose information was taken remains unknown, and the leak-site listing does not detail the specific data types beyond claiming that files were stolen.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch leaguecenter.org
Get alerted the next time leaguecenter.org files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about leaguecenter.org’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Details from the RansomHub Listing
The primary disclosure on the RansomHub onion site states that the League Education & Treatment Center suffered a ransomware intrusion and that attackers successfully exfiltrated internal files. No victim count, no sample documents, and no precise description of the records appear in the posting. The listing follows the group’s standard format: an organization name, a note of data theft, and the implicit threat of publication or further extortion if demands are not met. Public reporting on RansomHub indicates the group typically sets short deadlines once a victim is listed, though the exact deadline for this incident is not publicly visible.
Why This Matters for You and Your Family
When a service provider that works directly with children and vulnerable adults is breached, the ripple effects reach the families who rely on it. Internal files from such an organization can contain names, addresses, dates of birth, medical or educational notes, contact details for parents and guardians, and sometimes Social Security numbers. Even without an exact count, any family whose child or adult relative has received services from the League Education & Treatment Center should treat their information as at risk. Once stolen data leaves a secure environment it can surface on dark-web markets, in extortion campaigns, or as the foundation for identity theft months or years later.
The Doxxing and Identity-Chain Risks
Ransomware groups rarely stop at one dataset. A single exposed email or phone number from these internal files can be chained with information from earlier breaches to build a complete profile: home address, family members’ names, children’s dates of birth, and even gaming usernames. Attackers and identity thieves use these links to hijack accounts, impersonate victims, or launch spear-phishing campaigns against parents already managing complex care needs. Credential leaks like this one cascade into account takeovers that can compromise both adult and children’s gaming accounts, exposing additional personal details and photos that fuel further doxxing.