Ransomware victim disclosure
← All victimsFedcap Rehabilitation Services
listed as Fedcap · Claimed by Ransomhouse · listed 4 months ago
Status timeline
- Listed
Jan 8, 2026
- Data leaked
At a glance
- Group
- Ransomhouse
- Status
- Data leaked
- Country
- United States
- Sector
- Public Sector
- Listed on leak site
- Jan 8, 2026
- Data size
- 743 GB
- Ransom demanded
- $740
About the victim
AI dossier — public-source company profileFedcap Rehabilitation Services is a New York-based nonprofit organization and member of The Fedcap Group, founded approximately 87 years ago (circa 1936). The organization provides workforce development, educational services, and rehabilitation support to individuals with disabilities and other barriers to employment, operating multiple government contracts and placing thousands of people in jobs annually. It also runs social enterprises including digital imaging and document management services.
- Industry
- Nonprofit Workforce Development & Rehabilitation Services
- Founded
- 1936
Attack summary
Severity: critical — 743 GB of data from a nonprofit serving vulnerable populations (individuals with disabilities, low-income individuals) under numerous government contracts has been published, likely containing regulated PII at scale, potentially including medical/rehabilitation records and government contract data.RansomHouse claims to have encrypted systems and exfiltrated approximately 743 GB of data from Fedcap; the post indicates the data has been published ('data_published' status), suggesting exfiltration and public disclosure of stolen files.
Data the group says was taken
AI dossier — extracted from the leak post- Government contract records
- Employee records
- Client/beneficiary personal information
- Financial records
- Educational program records
- Internal organizational documents
What the group claims
Founded in 1935, Fedcap is a nonprofit organization that creates opportunities for people with barriers to economic well-being. Fedcap's headquarters is in New York City, New York.
The leak post
captured from the group's site```
{"data":[{"id":"a1894b76b7004c75a3a0845799af49956592e3d9","display":"animated","header":"HOT NEWS","info":" Trellix is a global cybersecurity company.","url":"","sort":1,"views":"436242"},{"id":"336b257f582b17573c97578efd4b22762bf77344","sort":2,"header":"Trellix (McAfee & FireEye)","url":"https://www.trellix.com/","private":"false","revenue":"1.5-2 B$","employees":"5000","info":"Trellix is a global cybersecurity company formed from the October 2021 merger of McAfee Enterprise and FireEye. It provides services to over 50,000 business and government customers worldwide, protecting more than 200 million endpoints. The companys open and native extended detection and response (XDR) platform helps organizations confronted by todays most advanced threats gain confidence in the protection and resilience of their operations. Trellix, along with an extensive partner ecosystem, accelerates technology innovation through machine learning and automation to empower over 40,000 business and government customers with living security","statusDate":"DEPENDS ON YOU","status":"EVIDENCE","published":"NOT YET","action":"Encrypted","actionDate":"17/04/2026","volume":"~","content":"cybersecurity.html"…Sources
Source
Indexed 4 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
