Ransomware victim disclosure
← All victimsFoundations to Freedom
listed as foundationstofreedom.org · Claimed by Incransom · listed 2 days ago
Status timeline
- ListedJul 28, 2026
- Data leakeddate unknown
At a glance
- Group
- Incransom
- Status
- Data leaked
- Country
- United States
- Listed on leak site
- Jul 28, 2026
About the victim
AI dossier — public-source company profileFoundations to Freedom is a US-registered 501(c)(3) non-profit organization headquartered in DeLand, Florida. It provides recovery housing, social adaptation programs, and comprehensive therapeutic support for individuals overcoming alcohol and substance abuse, as well as survivors of domestic violence.
- Industry
- Non-profit Social Services & Substance Abuse Recovery
- Address
- DeLand, Florida, USA
Attack summary
Severity: high — Non-profit serving vulnerable populations (substance abuse recovery and domestic violence survivors) with access to highly sensitive personal health and safety data. Exposure poses significant risk to client safety and privacy regardless of proof file count.The incransom group claims to have compromised Foundations to Freedom's systems and published data. No specific details about encryption, exfiltration scope, or data categories are stated in the available post excerpt.
Data the group says was taken
AI dossier — extracted from the leak post- Client recovery records
- Personal identifying information
- Therapeutic program documentation
- Domestic violence survivor records
What the group claims
Foundations to Freedom is a US-registered 501(c)(3) non-profit organization that provides recovery housing, social adaptation programs, and comprehensive therapeutic support for individuals overcoming alcohol and substance abuse, as well as survivors of domestic violence.The organization is dedicated to offering a safe, structured environment for individuals to rebuild their lives from the ground up and maintain long-term sobriety. It is headquartered in DeLand, Florida, USA
Sources
Source
Indexed 2 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

