afton.loc Listed by incransom Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Afton.loc was listed by the Incransom ransomware group on 3 November 2025, confirming that internal files had been exfiltrated in a ransomware attack. The number of people affected remains undisclosed; anyone who has an account or relationship with the organisation should check for official notices and change passwords or enable multi-factor authentication where possible.
On 3 November 2025 the domain afton.loc appeared on a listing claimed by the incransom ransomware group. The group states that internal files were taken in a ransomware attack. The number of people whose information may be involved remains unknown, and public detail on the precise contents is limited. For anyone who has interacted with the organisation—members, staff, donors or correspondents—the practical concern is straightforward: personal or organisational records that were never meant to leave its systems may now be in the hands of criminals who specialise in pressure and resale.
That uncertainty itself is the immediate stake. Without confirmed counts or file inventories, individuals cannot yet know whether their names, contact details, correspondence or other records are among the material. The listing is a claim, not an independent verification, yet the pattern of such claims is familiar enough that people connected to afton.loc have reason to treat the possibility seriously and take basic protective steps.
What happened
According to the available record, afton.loc was listed by the incransom ransomware group on 3 November 2025. The group claims that internal files were exfiltrated during a ransomware attack. No further technical details—such as the initial access method, the duration of the intrusion, the volume of data taken, or any ransom demand—have been publicly disclosed. The number of people affected is recorded as unknown. Independent confirmation of the breach beyond the group’s own listing has not been provided in the facts available.
The group behind it: incransom
Incransom is a ransomware operation that follows the now-common double-extortion model: data is copied out of the victim’s network before systems are encrypted, and the stolen material is used as leverage. If payment is not made, the group typically posts samples or full archives on a dedicated leak site to increase pressure and to advertise its capabilities to other potential victims. Like other groups of this type, it relies on public listings to demonstrate that it possesses the data and is prepared to release it. In the present case the listing of afton.loc is precisely such a claim; it should be read as an assertion by the actors rather than as independently verified fact. Prior public activity by incransom has followed the same pattern of data theft followed by leak-site publication when negotiations stall, but no additional statements specific to this victim beyond the listing itself are recorded here.
afton.loc and its sector
The organisation associated with afton.loc is described in the available summary as The Aetherius Society, a spiritual organisation founded in 1955 by Dr. George King. Its stated purpose is to spread and act upon teachings attributed to advanced extraterrestrial intelligences known as Cosmic Masters. The society promotes King Yoga, a practice oriented toward spiritual evolution, cosmic wisdom and service to humanity in preparation for what it terms the New Age. Its teachings address meditation, karma, reincarnation, UFOs and spiritual healing. Organisations of this character typically maintain membership rolls, correspondence, donation records, event registrations and internal administrative files. Because the work involves personal spiritual inquiry and community participation, the data held can include sensitive personal details alongside ordinary contact and financial information. A breach of such records therefore carries consequences both for the privacy of individuals and for the trust that underpins a voluntary spiritual community.
What was likely exposed
The only data type named in the available facts is “internal files” said to have been exfiltrated in the ransomware attack. No inventory of those files, no sample documents, and no confirmation of specific categories such as membership lists, financial records or personal correspondence have been publicly disclosed. Organisations of this kind commonly hold member contact information, donation histories, internal communications, event attendance data and administrative documents. Whether any or all of those categories were among the material taken remains unconfirmed. Readers should therefore treat any more detailed description of the exposed data as speculative until independent verification appears.
What's at stake
For individuals, the concrete risks include unwanted contact, targeted phishing that references genuine organisational details, and the possible misuse of personal or financial information if such records were present. For the organisation itself, the stakes include disruption of operations, erosion of member confidence, and the administrative burden of investigation and notification. Because the number of people affected is unknown and the exact file contents remain undisclosed, the scale of these risks cannot yet be quantified. The listing alone, however, is sufficient reason for caution.
Were you affected?
If you have had any relationship with afton.loc or The Aetherius Society—membership, donation, correspondence or employment—consider the following practical steps:
- Monitor financial and email accounts for unexpected activity or messages that reference the organisation.
- Change passwords used for any related accounts and enable multi-factor authentication where available.
- Treat unsolicited requests for personal information or payments with heightened scepticism.
- Retain any official notifications you may later receive from the organisation itself.
Public detail remains limited, so definitive confirmation that any particular person’s data was taken is not yet possible. Readers can run a free exposure scan of their email address to check whether that address has already appeared in other known breach data sets; such a scan does not prove involvement in this incident but can surface earlier exposures that warrant attention.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
bergen1.net Listed by incransom Ransomware Grouplafj.org Listed by incransom Ransomware Grouphttps://trustarholdingsllc.com/ https://vistlabs.com/ Listed by incransom Ransomware GroupOSI Systems, Inc. Listed by incransom Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the afton.loc Listed by incransom Ransomware Group →
Publicly posted by incransom — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.