American Association on Health and Disability Listed by sinobi Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
American Association on Health and Disability was listed by the sinobi ransomware group on 13 September 2025, indicating that internal files were taken in an attack whose exact date remains unknown. Individuals who may have had dealings with the organisation should review any communications from the group and take steps to protect their information.
On September 13, 2025, the American Association on Health and Disability was listed by the sinobi ransomware group. Public reporting indicates the group claims to have conducted a ransomware attack that involved the exfiltration of internal files. The number of people affected remains unknown, and further details about the scale, timing, and precise method of the incident have not been disclosed. For an organization that works on health equity and disability-related public health, any exposure of internal materials raises practical concerns about confidentiality and potential secondary risks to the communities it serves.
What is known so far rests on the group's leak-site listing and the limited summary that has circulated. No independent confirmation of the full scope has been made public, and the exact contents of the claimed files have not been itemized beyond the description of internal materials taken during a ransomware attack.
What happened
According to available reports dated September 13, 2025, the American Association on Health and Disability appeared on a listing associated with the sinobi ransomware group. The group claims that internal files were exfiltrated as part of a ransomware attack. No public figures have been released for the volume of data involved, the number of individuals whose information may have been included, or the exact date the intrusion occurred. The method of initial access, the duration of any unauthorized presence on systems, and whether encryption was also deployed remain undisclosed. In short, the public record consists of the listing itself and the statement that internal files were taken; everything else is unconfirmed.
The group behind it: sinobi
Sinobi is a ransomware operation that has appeared in public threat reporting as a group employing double-extortion tactics. Like many contemporary ransomware actors, it typically encrypts systems while also copying data and threatening to publish or sell the material if a ransom is not paid. The group maintains a leak site on which it posts victim names and, in some cases, samples or larger dumps of claimed data. Its activity has been tracked by security researchers as part of the broader ransomware ecosystem that targets organizations across sectors, often focusing on entities whose data holds operational or personal value. In this instance, the listing of the American Association on Health and Disability constitutes a claim by the group; it should be treated as such until independently verified. No specific statements attributed to sinobi about this victim beyond the listing and the assertion of internal-file exfiltration have been detailed in the available facts.
About American Association on Health and Disability
The American Association on Health and Disability focuses on improving overall health for people with disabilities through health promotion, wellness initiatives, policy advocacy, research, and public-health programs. Its work aims to reduce health disparities and advance health equity. The organization disseminates information on disability and health, including through its peer-reviewed Disability Health Journal, and provides resources intended for individuals with disabilities, healthcare professionals, researchers, and policymakers. Organizations of this type commonly maintain internal records related to program participants, research data, advocacy contacts, staff information, and operational documents. A breach affecting such an entity is consequential because the populations it serves often already face heightened privacy and discrimination risks; any compromise of related materials can amplify those concerns even when the precise data set remains unconfirmed.
The information in question
The facts state that internal files were exfiltrated in a ransomware attack. No further breakdown of file types, categories of personal information, or specific data elements has been publicly disclosed. The number of people affected is listed as unknown. Organizations engaged in disability health advocacy and research typically hold a range of materials that can include correspondence, program records, research datasets, contact lists, and administrative documents. Some of those materials may contain personally identifiable or health-related information, but it is not established that such data was present in the files claimed by the group. Exact contents remain unconfirmed, and any assessment of exposure must therefore remain provisional.
What's at stake
For individuals whose information might appear in internal files, the practical risks include potential misuse of contact details, exposure of sensitive personal circumstances, or secondary targeting such as phishing that leverages knowledge of an association with disability-related services. Even without confirmed personal data, the mere listing of an organization can create anxiety and prompt opportunistic fraud attempts that reference the incident. For the American Association on Health and Disability itself, the stakes include operational disruption, the cost of investigation and remediation, possible regulatory or contractual notification obligations, and reputational effects that could affect partnerships and funding. Because the scale and contents are undisclosed, the concrete impact on any given person cannot yet be measured; the prudent posture is to treat the claim seriously while awaiting clearer public information.
What to do if you're exposed
If you have a past or present connection to the American Association on Health and Disability—as a program participant, researcher, staff member, or contact—monitor accounts and communications for unusual activity. Enable multi-factor authentication where available, be skeptical of unsolicited messages that reference the organization or claim to offer help related to a breach, and consider placing fraud alerts with major credit bureaus if you believe personal identifiers may have been involved. Keep records of any suspicious contacts. Readers can also run a free exposure scan of their email address to check whether that address has already appeared in known breach datasets; such a check provides one additional data point but does not confirm or rule out involvement in this specific incident. Continue to follow official statements from the organization for any confirmed guidance or notification processes.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Greater Mental Health of New York Listed by sinobi Ransomware GroupCardiovascular Medical Group of Southern California (CVMG) Listed by sinobi Ransomware GroupCenter for Life Resources ECI Listed by sinobi Ransomware GroupFlorida Orthopaedic Associates Listed by sinobi Ransomware GroupLatest breaches
Publicly posted by sinobi — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.