Ransomware victim disclosure
← All victimsRockwood Retirement Communities
Claimed by Kairos · listed 3 months ago
Status timeline
- Listed
Feb 27, 2026
- Data leaked
At a glance
- Group
- Kairos
- Status
- Data leaked
- Country
- United States
- Sector
- Consumer Services
- Listed on leak site
- Feb 27, 2026
About the victim
AI dossier — public-source company profileRockwood Retirement Communities is a nonprofit organization with over 65 years of operation, headquartered in Spokane, Washington. It operates two Life Plan (continuing care retirement) communities in the Inland Northwest region. The organization is focused on mission-driven senior living services.
- Industry
- Senior Living & Retirement Communities
- Address
- Spokane, Washington, United States
Attack summary
Severity: critical — Rockwood operates senior living communities, meaning their data almost certainly includes regulated personal, medical, and financial information (PII, PHI) for elderly residents — a vulnerable population. Data has been published, indicating confirmed exfiltration of likely HIPAA-regulated sensitive data at scale.The Kairos ransomware group claims to have attacked Rockwood Retirement Communities, with the disclosure status indicating data has been published. The leak post does not specify whether encryption occurred, but the data_published status implies exfiltration of company data.
Data the group says was taken
AI dossier — extracted from the leak post- Resident personal information
- Employee records
- Financial records
- Healthcare/medical data
- Nonprofit operational data
What the group claims
With more than 65 years of mission-driven nonprofit service and two thriving Life Plan communities in Spokane, Washington, Rockwood Retirement is the recognized leader in senior living in the Inland Northwest. Our vision is simple: to create caring retirement communities that enrich the lives of seniors, every day.
Source
Indexed 3 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
