LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › American Addiction Centers Listed by rhysida Ransomware Group

HIGH severityUnverified claimHow we verify

American Addiction Centers Listed by rhysida Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·September 26, 2024
American Addiction Centers Listed by rhysida Ransomware Group

Reported September 26, 2024.

HIGH
Severity
September 26, 2024
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

American Addiction Centers was listed by the Rhysida ransomware group on September 26, 2024, after internal files were stolen in a ransomware attack. Anyone connected to the organization should check for official notices and review their accounts or records for signs of unauthorized activity.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

For people who have sought treatment through American Addiction Centers or whose personal details may appear in its records, a ransomware group's claim that it has taken internal files raises immediate practical questions. Sensitive health and personal information, if exposed, can create lasting risks of identity misuse, targeted fraud, or unwanted disclosure of private medical history. Public detail remains limited, yet the listing itself is enough to warrant careful attention from anyone connected to the organisation.

On 26 September 2024, American Addiction Centers was reported as listed by the rhysida ransomware group. The group claims that internal files were exfiltrated during a ransomware attack. The number of people affected is unknown, and the precise contents of the files have not been disclosed. What follows is a factual account of what is known, the nature of the claimed actor, the organisation involved, and the steps individuals can take.

Breaking down the breach

American Addiction Centers was listed by the rhysida ransomware group on or around 26 September 2024. According to the available report, the group asserts that internal files were exfiltrated as part of a ransomware attack. No further public confirmation of the intrusion method, the exact date of any compromise, the volume of data taken, or the number of individuals whose information may be involved has been provided. The scale of any impact therefore remains undisclosed. The listing itself constitutes a claim by the group rather than an independently verified statement of what occurred inside the organisation's systems.

Ransomware incidents of this type typically involve encryption of systems combined with data theft, after which the group pressures the victim by threatening to publish the material. In this case, only the claim of exfiltration of internal files has been stated. No dollar amounts, file counts, or specific system details appear in the public record of the incident.

Who is rhysida?

Rhysida is a ransomware group that became publicly active in 2023. It operates a double-extortion model: encrypting a victim's systems while also stealing data and threatening to leak it on a dedicated dark-web site if a ransom is not paid. The group has previously listed organisations across multiple sectors, including healthcare, education, and government-related entities. Its typical tactics include initial access through phishing or exploited vulnerabilities, followed by lateral movement, data staging, and deployment of ransomware. Rhysida often posts sample files or directories on its leak site to substantiate claims. In the present matter, the group's listing of American Addiction Centers should be treated as an unverified claim; no independent confirmation of the specific files or the success of any attack has been supplied in the available facts.

Who is American Addiction Centers?

American Addiction Centers was founded in 2007 and has grown into what it describes as the largest network of rehab facilities nationwide. It operates programs in California, Florida, Texas, Nevada, Massachusetts, Mississippi, New Jersey, and Rhode Island. Organisations of this kind provide residential and outpatient addiction treatment, counselling, and related clinical services. They routinely handle highly sensitive information: medical histories, treatment records, insurance details, payment data, contact information, and sometimes family or emergency-contact records. Because addiction treatment carries significant social stigma, any unauthorised exposure of such data can affect patients' privacy, employment, relationships, and willingness to seek future care. A claimed breach therefore carries particular weight for the people who have trusted the organisation with that information.

What was likely exposed

The facts state only that internal files were exfiltrated in a ransomware attack. No specific data types—such as names, Social Security numbers, medical diagnoses, or financial records—have been named. Exact contents therefore remain unconfirmed. Organisations that operate addiction-treatment networks typically maintain electronic health records, patient intake forms, billing and insurance files, staff records, and operational documents. Any of these categories could, in principle, appear among internal files, but that possibility is not established fact in this incident. Until more detail is released by the organisation or verified independently, it is not possible to state what was actually taken.

The real-world impact

For individuals whose information may have been involved, the primary risks are identity theft, financial fraud, and the unwanted disclosure of sensitive health details. Medical and addiction-related data can be used for targeted phishing, insurance fraud, or social engineering. Even if the files prove limited in scope, the mere possibility of exposure can cause anxiety and require ongoing vigilance. For the organisation, a ransomware claim can disrupt operations, damage trust among patients and referring clinicians, and trigger regulatory scrutiny under health-privacy rules. Recovery often involves system restoration, forensic investigation, and notification processes whose costs and timelines remain unknown here because the number of people affected and the precise data involved have not been disclosed.

Because the scale is unknown, it is not possible to quantify how many people face elevated risk. Anyone who has been a patient, family member, or employee of American Addiction Centers should treat the claim as a prompt for caution rather than as proof that their own records were taken.

What to do if you're exposed

If you have a past or present connection to American Addiction Centers, begin by monitoring financial accounts and credit reports for unusual activity. Consider placing a fraud alert or credit freeze with the major credit bureaus. Be alert to phishing emails or calls that reference addiction treatment or personal medical details; do not click links or provide information in response to unsolicited contact. Review any notices the organisation may issue and follow official guidance if it becomes available. As a practical next step, you can run a free exposure scan of your email address to check whether your information has already appeared in known breach data sets. That check will not confirm or rule out involvement in this specific incident, but it can surface other exposures that warrant attention. Stay calm, act methodically, and rely on verified sources rather than unverified claims circulating online.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyAmerican Addiction Centers security record
56/100
DoxxScan™ · Elevated doxx risk
D- 44Very poor record

2 reported incidents on record.

See American Addiction Centers’s full breach history →
RelatedMore incidents at American Addiction Centers

More recent breaches

Sunflower Medical Group Listed by rhysida Ransomware GroupDecember 15, 2024Hope Valley Recovery Listed by rhysida Ransomware GroupNovember 1, 2024Easterseals Listed by rhysida Ransomware GroupOctober 23, 2024Axis Health System Listed by rhysida Ransomware GroupOctober 7, 2024

Latest breaches

Read GalaxyWarden’s full analysis of the American Addiction Centers Listed by rhysida Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by rhysida — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram