LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Derp.org Listed by IMNCrew Ransomware Group

HIGH severityUnverified claimHow we verify

Derp.org Listed by IMNCrew Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·May 5, 2025
Derp.org Listed by IMNCrew Ransomware Group

Reported May 5, 2025.

HIGH
Severity
May 5, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Derp.org has been listed by the IMNCrew ransomware group, with internal files reported to have been exfiltrated in an attack. The incident came to light on 5 May 2025; individuals who may have had data with Derp.org should review their accounts and security settings.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

People who work for or have retired from the City and County of Denver, along with certain Denver Health employees and DERP staff, may now face questions about whether their personal and financial details were caught up in a ransomware incident. Public reporting shows that Derp.org, the Denver Employees Retirement Plan, was listed by the IMNCrew ransomware group on May 05, 2025. The number of people affected remains unknown, and the only confirmed detail is that internal files were allegedly exfiltrated. For anyone whose retirement security depends on this plan, that uncertainty itself is the immediate practical stake.

Because DERP manages defined-benefit pensions for more than 10,800 retirees and beneficiaries and nearly 10,000 active members, even limited exposure of internal records can create lasting worry about identity misuse, pension-related fraud, or unwanted contact. The listing is a claim by the group rather than an independently verified confirmation of every detail, yet it is enough to warrant careful attention from those who rely on the plan.

Inside the incident

According to the available public record, Derp.org appeared on an IMNCrew leak-site listing dated May 05, 2025. The group claims that internal files were exfiltrated as part of a ransomware attack. No further technical details—such as the precise date the intrusion began, the method of initial access, the volume of data taken, or any ransom demand—have been disclosed in the facts provided. The number of individuals whose information may be involved is listed as unknown. Public reporting does not confirm whether systems were encrypted, whether any data has been released, or whether the organisation has issued its own statement verifying the claim. In short, the incident is known primarily through the group’s listing and the description of internal-file exfiltration; everything else remains unconfirmed at this time.

The group behind it: IMNCrew

IMNCrew is a ransomware operation that has appeared in public threat reporting as a group that practices double extortion: it encrypts systems where possible and simultaneously steals data, then threatens to publish the material on a dedicated leak site if its demands are not met. Like many contemporary ransomware crews, it typically posts victim names and sample files to pressure organisations into payment. Public knowledge of the group’s broader activity shows a pattern of targeting entities that hold sensitive personal or financial records, though each listing must be treated as a claim until independently verified. In this case, the facts state only that Derp.org was listed and that internal files were said to have been exfiltrated; no additional statements or sample data specific to this victim are recorded in the available information. Readers should therefore regard the listing as an unverified assertion by the group rather than established fact.

Derp.org and its sector

Derp.org is the public face of the Denver Employees Retirement Plan, a defined-benefit pension system established on January 1, 1963. It serves eligible Career Service employees of the City and County of Denver, certain employees of the Denver Health and Hospital Authority, and its own staff. The plan currently pays monthly pension benefits to more than 10,800 retirees and beneficiaries and holds the future financial security of almost 10,000 active members. Public-sector retirement systems of this kind routinely maintain detailed records of employment history, salary data, Social Security numbers, bank-account information for direct deposits, beneficiary designations, and medical or disability documentation when relevant to benefit calculations. Because these organisations sit at the intersection of government employment and long-term financial planning, a breach can affect both current workers and people who left city service years earlier. The consequential nature of any incident here stems directly from the sensitivity and longevity of the data such plans must keep to administer benefits accurately.

What data was at risk

The facts name only “internal files exfiltrated in ransomware attack.” No inventory of specific data categories—such as names, Social Security numbers, bank details, or medical records—has been publicly confirmed. Organisations that administer public-employee pensions typically hold precisely those categories of information, along with contribution histories, beneficiary forms, and correspondence. Until a full accounting is released by Derp.org or an independent investigator, however, the exact contents of the exfiltrated files remain unconfirmed. Readers should therefore treat any assumption about particular data elements as speculative.

The real-world impact

For individuals, the primary risks are identity theft, fraudulent claims against pension accounts, and targeted phishing that references real employment or retirement details. Because pension records often contain decades-old information, the exposure window can be long; a Social Security number or bank routing number taken today could be misused years later. For the organisation itself, the incident raises operational questions about member trust, potential regulatory notification duties, and the cost of forensic investigation and remediation. No dollar figures, member counts, or confirmed cases of fraud have been reported in the available facts, so the scale of harm remains unknown. The practical consequence is simply that people who depend on DERP for retirement income now have reason to monitor their financial accounts and credit reports more closely than before.

What to do if you're exposed

If you are a current or former Denver employee, a Denver Health worker covered by the plan, a retiree, or a beneficiary, begin by reviewing recent account statements and credit reports for unfamiliar activity. Place a free fraud alert or credit freeze with the major credit bureaus if you notice anything suspicious. Change passwords on any financial or government portals that use the same email address associated with your DERP account, and enable multi-factor authentication wherever it is offered. Keep records of any unusual correspondence that references your pension or employment history. Finally, you can run a free exposure scan of your email address to check whether that address has already appeared in known breach data sets; doing so provides one additional data point while official details remain limited.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyDerp.org security record
87/100
DoxxScan™ · Low doxx risk
B 80Good record

1 reported incident on record.

See Derp.org’s full breach history →

More recent breaches

Jansenfurniture.com Listed by IMNCrew Ransomware GroupSeptember 16, 2025Apntelecom.com Listed by IMNCrew Ransomware GroupJuly 4, 2025Stiga.com Listed by IMNCrew Ransomware GroupMay 20, 2025Goodson.com Listed by IMNCrew Ransomware GroupMay 5, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the Derp.org Listed by IMNCrew Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by imncrew — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram