Ransomware victim disclosure
← All victimsIKRON Corporation
listed as ikron.org · Claimed by Lockbit5 · listed 3 months ago
Status timeline
- ListedMar 30, 2026
- Data leakeddate unknown
At a glance
- Group
- Lockbit5
- Status
- Data leaked
- Country
- United States
- Sector
- Education
- Listed on leak site
- Mar 30, 2026
About the victim
AI dossier — public-source company profileIKRON Corporation (Integration of Knowledge and Resources for Occupational Needs) is a nonprofit organization founded in 1969 that provides integrated behavioral health and employment services across the greater Cincinnati, Ohio and Seattle, Washington areas. Services include employment services, behavioral health, youth services, peer services, education, health home, and integrated care. The organization operates at multiple locations and accepts donations, indicating a community-focused nonprofit structure.
- Industry
- Behavioral Health & Employment Services
- Address
- Cincinnati, Ohio and Seattle, Washington areas, United States
- Founded
- 1969
Attack summary
Severity: critical — IKRON is a behavioral health and social services provider handling sensitive medical and mental health records, employment data, and youth services data — all categories of regulated/sensitive PII. Data has been published, confirming exfiltration of likely HIPAA-covered health information at scale.LockBit 5 claims to have attacked IKRON Corporation and has published data (disclosed status: data_published), suggesting exfiltration of organizational data. The specific nature of the exfiltrated data has not been fully detailed in the truncated post.
Data the group says was taken
AI dossier — extracted from the leak post- Behavioral health client records
- Employment services records
- Youth services records
- Organizational/administrative data
- Personally identifiable information (PII)
What the group claims
IKRON (Integration of Knowledge and Resources for Occupational Needs) was founded in 1969 as the Uni...
Sources
Source
Indexed 3 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

