On May 28, 2025, the Connecticut nonprofit Waveny appeared on the leak site of the qilin ransomware group, with internal files reportedly exfiltrated during a ransomware attack. The organization, which has provided independent living, assisted care, memory care, short-term rehabilitation, and at-home services since 1975, now faces the public exposure of sensitive internal documents that could contain personal information belonging to residents, patients, employees, and their families.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch waveny.org
Get alerted the next time waveny.org files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about waveny.org’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting indicates that qilin listed Waveny on its leak site on May 28, 2025. The data consists of internal files exfiltrated during a ransomware incident. The exact number of people affected remains unknown, and the specific types of personal information contained in the files have not been fully detailed in available reporting. Waveny is a nonprofit that has served its community for more than 50 years, operating facilities and services focused on senior care and rehabilitation.
Why This Matters for You and Your Family
When a care provider like Waveny is hit, the people most likely to be exposed are ordinary families who trusted the organization with medical records, insurance details, Social Security numbers, addresses, and contact information. If your parent, grandparent, spouse, or child has ever received care from Waveny or a similar nonprofit, your household data may now sit in a ransomware leak. Stolen internal files often contain exactly the combination of details that allow identity theft, insurance fraud, or targeted scams against older adults and their adult children who manage their affairs.
Even when victim counts are listed as unknown, the breach still creates immediate risk. Families dealing with memory care or rehabilitation services frequently share extensive personal and financial data. Once that information leaves the organization’s control, it can surface months or years later in fraud schemes or phishing campaigns tailored to your family’s specific situation.