Ransomware victim disclosure
← All victimsCOMHAR
Claimed by Worldleaks · listed 2 days ago
Status timeline
- ListedJul 1, 2026
- Data leakeddate unknown
At a glance
- Group
- Worldleaks
- Status
- Data leaked
- Country
- United States
- Sector
- Business Services
- Listed on leak site
- Jul 1, 2026
About the victim
AI dossier — public-source company profileCOMHAR is a mental health and social services organization providing outpatient counseling, medication-assisted treatment (MAT), residential services, psychiatric rehabilitation, and specialized programs for vulnerable populations including those with intellectual/developmental disabilities, LGBTQIA+ individuals, and people with HIV/AIDS. The organization operates in the US and marked its 50th anniversary.
- Industry
- Mental Health & Substance Abuse Treatment Services
Attack summary
Severity: high — COMHAR handles sensitive healthcare data (mental health, addiction treatment, vulnerable populations). Confirmed data publication involving a healthcare/social services provider with regulated PII warrants high severity, despite lack of detailed proof inventory in the truncated post.The worldleaks group claims to have breached COMHAR and published data. The leak post content is marked as AI-generated with no substantive detail provided regarding what was encrypted, exfiltrated, or the scope of compromise.
Data the group says was taken
AI dossier — extracted from the leak post- Patient/member health records
- Mental health treatment data
- Substance abuse treatment information
- Personal identifying information
Original description
AI-summarised, not from the leak postN/A
Sources
Source
Indexed 2 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

