Ransomware victim disclosure
← All victimsStepping Stone of San Diego
listed as steppingstonesd.org · Claimed by Blacksuit · listed 2 years ago
Status timeline
- ListedNov 12, 2024
- Data leakeddate unknown
At a glance
- Group
- Blacksuit
- Status
- Data leaked
- Country
- United States
- Sector
- Education
- Listed on leak site
- Nov 12, 2024
About the victim
AI dossier — public-source company profileStepping Stone of San Diego is a non-profit organization founded in 1976 that provides residential and outpatient alcohol and drug treatment services, with specialized focus on the LGBTQ community. The organization offers residential treatment, outpatient programs, sober living facilities, and continuing care services across San Diego.
- Industry
- Substance Abuse & Mental Health Treatment
- Founded
- 1976
Attack summary
Severity: medium — Data published status indicates exfiltration occurred; non-profit healthcare/mental health treatment provider holding sensitive PII and health records of vulnerable populations (substance abuse clients, LGBTQ individuals). However, no proof files shown, no specific data inventory disclosed, and no operational disruption claimed. Sensitivity is elevated due to nature of records but confidence in actual exposure is limited.Blacksuit claims to have compromised Stepping Stone of San Diego. The leak post provides only generic description of the organization with no specific details of data exfiltrated, encryption, or operational impact stated.
Data the group says was taken
AI dossier — extracted from the leak post- Patient/client records
- Personal health information
- Financial data
Original description
AI-summarised, not from the leak postStepping Stones is a non-profit organization focused on providing educational and therapeutic services to individuals with developmental disabilities. It offers a range of programs aimed at enhancing the quality of life and fostering independence for children and adults. The organization emphasizes personalized care, community integration, and skill development to support its members and their families.
Sources
Source
Indexed 2 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

