Ransomware victim disclosure
← All victimsSalvation Army
Claimed by bravox · listed 5 hours ago
Status timeline
- Listed
May 23, 2026
- Data leaked
At a glance
- Group
- bravox
- Status
- Data leaked
- Country
- CA
- Sector
- Consumer Services
- Listed on leak site
- May 23, 2026
About the victim
AI dossier — public-source company profileThe Salvation Army is Canada's largest non-governmental direct provider of social services, offering emergency aid, shelter, food assistance, addiction recovery, disaster relief, and community support. Operating across Canada and Bermuda, the organization served over 3 million visits last year and provides 5,500 shelter and mental health beds nightly.
- Industry
- Non-profit Social Services & Charitable Organization
- Address
- 2 Overlea Boulevard, Toronto, ON, Canada
Attack summary
Severity: medium — Disclosed status is 'data_published' but the actual leak post provided contains no substantive detail on exfiltration, proof files, or sensitive data categories. The vague claim combined with absence of demonstrated proof or ransom demand suggests a preliminary or low-confidence disclosure. However, given the organization's role handling vulnerable populations (shelter residents, addiction recovery clients, disaster victims), any confirmed breach could expose sensitive personal and health informThe bravox ransomware group claims to have attacked The Salvation Army. The leak post provides minimal detail on the nature of the breach—whether data was exfiltrated, encrypted, or both—and does not specify what data categories are at stake.
What the group claims
Provides social services, emergency aid, rehabilitation, and community support.
Sources
Source
Indexed 5 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.
