Ransomware victim disclosure
← All victimsThe Associated: Jewish Federation of Baltimore
listed as associated.org · Claimed by Lockbit5 · listed 4 months ago
Status timeline
- ListedFeb 23, 2026
- Data leakeddate unknown
At a glance
- Group
- Lockbit5
- Status
- Data leaked
- Country
- United States
- Listed on leak site
- Feb 23, 2026
About the victim
AI dossier — public-source company profileThe Associated: Jewish Federation of Baltimore is a nonprofit organization dedicated to supporting and nurturing Jewish life in Baltimore and beyond. It operates a broad range of programs spanning social services, education, community building, Israel partnerships, and philanthropy. The organization also manages investment services (JCIF), grant opportunities, and partners with numerous agencies across the Baltimore region.
- Industry
- Nonprofit Jewish Community Federation & Philanthropy
- Address
- Baltimore, Maryland, United States
Attack summary
Severity: high — Data has been published (disclosed status: data_published) by the group, indicating confirmed exfiltration. As a nonprofit federation handling donor PII, financial records, investment services, and sensitive community data (including antisemitic incident reports and vulnerable population services such as trauma, abuse, and mental health), the exposure represents significant sensitive personal and financial data at scale.LockBit 5 claims to have attacked The Associated: Jewish Federation of Baltimore and has disclosed data as published, though no specific data size or ransom amount was stated. The disclosure status indicates data has been published, suggesting exfiltration of organizational records.
Data the group says was taken
AI dossier — extracted from the leak post- Donor records
- Financial/investment data
- Employee/staff records
- Partner agency information
- Grant and fundraising records
- Community member PII
What the group claims
The Associated: Jewish Federation of Baltimore is dedicated to supporting and nurturing Jewish life...
Sources
Source
Indexed 4 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

