Ransomware victim disclosure
← All victimsSoutheastern Conference of Seventh-day Adventists
Claimed by NIGHT SPIRE · listed 18 hours ago
Status timeline
- Listed
Jun 6, 2026
Current state: Listed for ransom
At a glance
- Group
- NIGHT SPIRE
- Status
- Listed for ransom
- Country
- US
- Sector
- Religious Organization
- Listed on leak site
- Jun 6, 2026
- Data size
- 600 GB
About the victim
AI dossier — public-source company profileThe Southeastern Conference of Seventh-day Adventists (SECSDA) is a regional administrative body of the Seventh-day Adventist Church serving the southeastern United States. The organization coordinates ministries, events, disaster response training, and community services across its member churches and institutions.
- Industry
- Religious Organization
Attack summary
Severity: medium — Confirmed exfiltration of sensitive organizational data including financial records, HR data, and employee PII at scale (600 GB). However, the leak post shows 'Data is not available now' for the SECSDA entry specifically, indicating proof may have been removed or was never publicly displayed. The organization is not a regulated financial or medical entity, limiting critical classification despite significant data exposure.NIGHT SPIRE claims to have exfiltrated approximately 600 GB of data from SECSDA, including financial documents, HR records, banking information, employee personal data, and organizational records. The group listed the victim on their leak site but indicates that proof files are no longer available.
Data the group says was taken
AI dossier — extracted from the leak post- Financial documents and records
- HR data and employee personal information
- Banking and accounting records
- Tax returns and QuickBooks files
- Employee email and SMS data
- Contracts and proposals
- Technical and business strategy documents
- Database backups (MSSQL)
The leak post
captured from the group's site- Financial Documents- HR Data- Supervisor's Information Data is not available now. Data is not available now. Data is not available now. [la familia adualt day center](http://www.lafamiliaadultdaycenter.com) Data is not available now. Data is not available now. - QuickBooks Files- Scanned tax returns- Proposal, Contrats- QuickBooks automated backups - Banking & Financial Records- Personal data- Critical POS Data - Banking & Financial Data- Accounting & Tax Records - Financial & Accounting Records- Human Resources- Sales & Marketing - Sales Related Documents- Human Resources- Sensitive Employee Records- Email and SMS Data Data is not available now. - Technical Documents- Financial Sheets- Contracts & Invoices- Business strategy files - MSSQL-DB- HR Documents- Contracts Data is not available now. [Progressive Oral Surgery & Implantology](http://nspirep7orjq73k2x2fwh2mxgh74vm2now6cdbnnxjk2f5wn34bmdxad.onion/progressiveoralsurgery.com) - Patients Information Records- Financial Records [The Country Club of Darien](http://nspirep7orjq73k2x2fwh2mxgh74vm2now6cdbnnxjk2f5wn34bmdxad.onion/CCDarien.org) - Sales / agent / commercial operations- Industrial / manufacturing / tooling business dat…
Screenshot of the leak post

Sources
Source
Indexed 18 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.
