Derp.org Listed by IMNCrew Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Derp.org has been listed by the IMNCrew ransomware group, with internal files reported to have been exfiltrated in an attack. The incident came to light on 5 May 2025; individuals who may have had data with Derp.org should review their accounts and security settings.
People who work for or have retired from the City and County of Denver, along with certain Denver Health employees and DERP staff, may now face questions about whether their personal and financial details were caught up in a ransomware incident. Public reporting shows that Derp.org, the Denver Employees Retirement Plan, was listed by the IMNCrew ransomware group on May 05, 2025. The number of people affected remains unknown, and the only confirmed detail is that internal files were allegedly exfiltrated. For anyone whose retirement security depends on this plan, that uncertainty itself is the immediate practical stake.
Because DERP manages defined-benefit pensions for more than 10,800 retirees and beneficiaries and nearly 10,000 active members, even limited exposure of internal records can create lasting worry about identity misuse, pension-related fraud, or unwanted contact. The listing is a claim by the group rather than an independently verified confirmation of every detail, yet it is enough to warrant careful attention from those who rely on the plan.
Inside the incident
According to the available public record, Derp.org appeared on an IMNCrew leak-site listing dated May 05, 2025. The group claims that internal files were exfiltrated as part of a ransomware attack. No further technical details—such as the precise date the intrusion began, the method of initial access, the volume of data taken, or any ransom demand—have been disclosed in the facts provided. The number of individuals whose information may be involved is listed as unknown. Public reporting does not confirm whether systems were encrypted, whether any data has been released, or whether the organisation has issued its own statement verifying the claim. In short, the incident is known primarily through the group’s listing and the description of internal-file exfiltration; everything else remains unconfirmed at this time.
The group behind it: IMNCrew
IMNCrew is a ransomware operation that has appeared in public threat reporting as a group that practices double extortion: it encrypts systems where possible and simultaneously steals data, then threatens to publish the material on a dedicated leak site if its demands are not met. Like many contemporary ransomware crews, it typically posts victim names and sample files to pressure organisations into payment. Public knowledge of the group’s broader activity shows a pattern of targeting entities that hold sensitive personal or financial records, though each listing must be treated as a claim until independently verified. In this case, the facts state only that Derp.org was listed and that internal files were said to have been exfiltrated; no additional statements or sample data specific to this victim are recorded in the available information. Readers should therefore regard the listing as an unverified assertion by the group rather than established fact.
Derp.org and its sector
Derp.org is the public face of the Denver Employees Retirement Plan, a defined-benefit pension system established on January 1, 1963. It serves eligible Career Service employees of the City and County of Denver, certain employees of the Denver Health and Hospital Authority, and its own staff. The plan currently pays monthly pension benefits to more than 10,800 retirees and beneficiaries and holds the future financial security of almost 10,000 active members. Public-sector retirement systems of this kind routinely maintain detailed records of employment history, salary data, Social Security numbers, bank-account information for direct deposits, beneficiary designations, and medical or disability documentation when relevant to benefit calculations. Because these organisations sit at the intersection of government employment and long-term financial planning, a breach can affect both current workers and people who left city service years earlier. The consequential nature of any incident here stems directly from the sensitivity and longevity of the data such plans must keep to administer benefits accurately.
What data was at risk
The facts name only “internal files exfiltrated in ransomware attack.” No inventory of specific data categories—such as names, Social Security numbers, bank details, or medical records—has been publicly confirmed. Organisations that administer public-employee pensions typically hold precisely those categories of information, along with contribution histories, beneficiary forms, and correspondence. Until a full accounting is released by Derp.org or an independent investigator, however, the exact contents of the exfiltrated files remain unconfirmed. Readers should therefore treat any assumption about particular data elements as speculative.
The real-world impact
For individuals, the primary risks are identity theft, fraudulent claims against pension accounts, and targeted phishing that references real employment or retirement details. Because pension records often contain decades-old information, the exposure window can be long; a Social Security number or bank routing number taken today could be misused years later. For the organisation itself, the incident raises operational questions about member trust, potential regulatory notification duties, and the cost of forensic investigation and remediation. No dollar figures, member counts, or confirmed cases of fraud have been reported in the available facts, so the scale of harm remains unknown. The practical consequence is simply that people who depend on DERP for retirement income now have reason to monitor their financial accounts and credit reports more closely than before.
What to do if you're exposed
If you are a current or former Denver employee, a Denver Health worker covered by the plan, a retiree, or a beneficiary, begin by reviewing recent account statements and credit reports for unfamiliar activity. Place a free fraud alert or credit freeze with the major credit bureaus if you notice anything suspicious. Change passwords on any financial or government portals that use the same email address associated with your DERP account, and enable multi-factor authentication wherever it is offered. Keep records of any unusual correspondence that references your pension or employment history. Finally, you can run a free exposure scan of your email address to check whether that address has already appeared in known breach data sets; doing so provides one additional data point while official details remain limited.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Jansenfurniture.com Listed by IMNCrew Ransomware GroupApntelecom.com Listed by IMNCrew Ransomware GroupStiga.com Listed by IMNCrew Ransomware GroupGoodson.com Listed by IMNCrew Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Derp.org Listed by IMNCrew Ransomware Group →
Publicly posted by imncrew — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.