Ransomware victim disclosure
← All victimsLGBTQ Center Orange county
Claimed by INC Ransom · listed 5 months ago
Status timeline
- ListedJan 28, 2026
- Data leakeddate unknown
At a glance
- Group
- INC Ransom
- Status
- Data leaked
- Country
- United States
- Sector
- Public Sector
- Listed on leak site
- Jan 28, 2026
About the victim
AI dossier — public-source company profileLGBTQ Center Orange County is a 501(c)(3) non-profit community-based organization established as a volunteer group in 1971 and incorporated in 1975. It provides services to more than 20,000 individuals annually across a broad spectrum of culture, ethnicity, age, and economic background in Orange County, California. The Center offers support and community services to LGBTQ individuals and their allies.
- Industry
- Non-Profit Community & Social Services
- Founded
- 1971
Attack summary
Severity: critical — The organization serves over 20,000 individuals annually, many of whom are likely to have shared sensitive personal information (including health, identity, and financial data) with an LGBTQ social services provider. Exfiltration and threatened publication of such records constitutes a critical disclosure of sensitive PII for a vulnerable population, with significant potential for harm including discrimination and targeted harassment.INC Ransom claims to have obtained data from LGBTQ Center Orange County and states that all information will be published the following week; the post indicates exfiltration with imminent full data publication.
Data the group says was taken
AI dossier — extracted from the leak post- Client/beneficiary personal records
- Organizational documents
- Internal communications
- Staff records
What the group claims
The LGBTQ Center OC was established as a volunteer organization in 1971 and incorporated in 1975 as a 501(c)(3) non-profit community-based organization. The Center provides services to more than 20,000 individuals annually across a broad spectrum of culture, ethnicity, age, and economic background. We will publish all the information next week.
Source
Indexed 5 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

