Ransomware victim disclosure
← All victimsLGBTQ Center Orange county
Claimed by Incransom · listed 5 months ago
Status timeline
- ListedJan 28, 2026
- Data leakeddate unknown
At a glance
- Group
- Incransom
- Status
- Data leaked
- Country
- United States
- Sector
- Public Sector
- Listed on leak site
- Jan 28, 2026
About the victim
AI dossier — public-source company profileLGBTQ Center Orange County (also known as The Center OC) is a 501(c)(3) non-profit community-based organization established in 1971 and incorporated in 1975. It provides services to more than 20,000 individuals annually across a broad spectrum of culture, ethnicity, age, and economic background in Orange County, California. The organization operates as a volunteer-rooted community center serving LGBTQ+ individuals and allies.
- Industry
- Non-Profit Community & Social Services
- Founded
- 1971
Attack summary
Severity: critical — The victim is a non-profit serving LGBTQ+ individuals, meaning exfiltrated data likely contains sensitive PII — including sexual orientation, gender identity, mental health, and potentially medical or financial records — for over 20,000 clients annually. Public disclosure of such data poses acute personal safety and discrimination risks to a vulnerable population, meeting the threshold for critical severity.The Incransom group claims to have obtained data from LGBTQ Center Orange County and states they will publish all information the following week, indicating exfiltration of organizational data with imminent full disclosure threatened.
Data the group says was taken
AI dossier — extracted from the leak post- Organizational records
- Client/member personal information
- Staff and volunteer data
- Financial records (probable)
What the group claims
The LGBTQ Center OC was established as a volunteer organization in 1971 and incorporated in 1975 as a 501(c)(3) non-profit community-based organization. The Center provides services to more than 20,000 individuals annually across a broad spectrum of culture, ethnicity, age, and economic background. We will publish all the information next week.
Sources
Source
Indexed 5 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

