LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surface
Recent BreachesData breach tracker

Recent Breaches › Eagle Crest Communities Listed by anubis Ransomware Group

HIGH severityUnverified claimHow we verify

Eagle Crest Communities Listed by anubis Ransomware Group: What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·July 26, 2026
Eagle Crest Communities Listed by anubis Ransomware Group

Reported July 26, 2026.

HIGH
Severity
1
Data types exposed
July 26, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Eagle Crest Communities was listed by the anubis ransomware group on July 26, 2026, after internal files were exfiltrated in an attack whose occurrence date has not been established. Individuals who may have been impacted should check the organisation’s notices and monitor their accounts for any signs of misuse.

Severity & verification
HIGH severityUnverified claim
Contact / identity PII exposed.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Was your email in the Eagle Crest Communities Listed by anubis Ransomware Group breach?
See every leak tied to your email — not just this one. 15-second check, no card, no account.

Ransomware groups continue to target healthcare and senior-care providers, drawn by the sensitivity of the records those organisations hold and the operational pressure that can follow disruption. In that landscape, listings on criminal leak sites have become a common way for attackers to assert leverage, even when independent confirmation remains limited.

Eagle Crest Communities, an elderly care service, was listed by the anubis ransomware group in a report dated July 26, 2026. Public detail describes a patient and employee data breach involving internal files said to have been exfiltrated in a ransomware attack. The number of people affected is unknown. The listing is a claim by the group; fuller independent verification of scope and contents has not been set out in the available facts.

Inside the incident

According to the reported summary, Eagle Crest Communities experienced a ransomware attack in which internal files were exfiltrated. The incident is characterised as a patient and employee data breach at an elderly care service. The organisation was listed by the anubis ransomware group, with the report dated July 26, 2026.

Publicly provided facts do not disclose how the attackers gained access, whether systems were encrypted, how long any intrusion lasted, or what volume of data was taken. The number of people affected is unknown. Beyond the description of internal files exfiltrated in a ransomware attack and the characterisation as a patient and employee data breach, specific file inventories, timelines, and confirmation steps are not detailed in the available record. The anubis listing itself should be read as the group’s claim that it holds or has published material related to the organisation.

Inside anubis

Anubis is known in public reporting as a ransomware operation that pairs data theft with encryption or the threat of publication. Like other groups in this category, it has typically sought to pressure victims by exfiltrating files and then listing organisations on a leak site, sometimes releasing samples or larger archives if demands are not met. Tactics associated with such groups often include initial access through compromised credentials, phishing, or exposed remote services, followed by lateral movement, data staging, and deployment of ransomware—though the precise path used against any single victim is not always published.

Notable prior activity attributed to anubis in open sources fits the broader pattern of double-extortion ransomware: name-and-shame listings, claims of stolen internal documents, and deadlines tied to payment. For this incident, the facts state only that Eagle Crest Communities was listed and that internal files were described as exfiltrated. No further claims by the group about this specific victim—such as ransom amounts, sample file names, or proof packs—are included in the provided record, and none should be assumed.

About Eagle Crest Communities

Eagle Crest Communities is identified in the facts as an elderly care service. Organisations in this sector typically operate residential, assisted-living, or related care settings for older adults. They routinely manage clinical and personal information, billing and insurance records, staff employment files, and day-to-day operational documents needed to deliver care and meet regulatory obligations.

A breach affecting such a provider is consequential because the population served is often older and may be more vulnerable to fraud, medical identity misuse, or distress if private health and personal details circulate. Employees’ data can also expose staff to identity theft or targeted scams. Operational disruption in care settings can affect continuity of services, though the facts here do not describe outages or clinical impact. The combination of patient-related and employee-related information is why listings of senior-care organisations draw particular attention from investigators, regulators, and affected families.

What was likely exposed

The facts name the exposed material as internal files exfiltrated in a ransomware attack and summarise the event as a patient and employee data breach. Exact inventories, record counts, and field-level contents are not disclosed in the available detail. For an elderly care service, internal files of this kind often include categories such as those below; these are typical holdings for the sector, not a confirmed list from this incident:

Because the public facts do not itemise what was taken, any assumption that a specific document type was or was not included remains unconfirmed. Readers should treat the patient-and-employee characterisation as the reported framing, not as a full forensic inventory.

What's at stake

For individuals, exposure of patient or resident data can mean risk of medical identity theft, fraudulent billing, targeted phishing that references real care details, or unwanted contact. Employee data can enable tax fraud, account takeover, or scams that impersonate an employer. Older adults and their families may face extra difficulty monitoring credit, insurance statements, and care-related correspondence if they are less familiar with digital alerts.

For the organisation, stakes include regulatory notification duties common in healthcare and long-term care, potential contractual obligations to partners and insurers, reputational harm, and the cost of investigation, containment, and support for affected people. Ransomware incidents can also interrupt administrative systems even when clinical care continues. None of these outcomes is stated as having occurred in the facts; they are the concrete risks that follow when internal care-sector files are claimed to have been stolen. The unknown number of people affected leaves the full human scale of the event unclear until more detail is published by the organisation or authorities.

If your data was in this breach

If you are a resident, family member, or employee connected to Eagle Crest Communities, treat the report as a reason to increase monitoring rather than as proof that your specific file was taken. Practical first steps include watching bank, credit card, and insurance statements for unfamiliar activity; placing fraud alerts or credit freezes with major credit bureaus if you are in a jurisdiction where that is available; being sceptical of unexpected calls or emails that cite the breach or ask for passwords, payment, or one-time codes; and using unique passwords with multi-factor authentication on email and financial accounts. If the organisation issues official notice or a call centre, prefer those channels over unsolicited messages.

You can also run a free exposure scan of your email address to check whether your information has already surfaced in known breach data sets, which may help you prioritise password changes and monitoring. Keep records of any suspicious contact, and consult official guidance from consumer-protection or healthcare regulators in your area if you believe you have been targeted. Public detail on this incident remains limited; further clarity will depend on what Eagle Crest Communities and investigators eventually confirm beyond the anubis listing and the reported summary of internal files and patient and employee data.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyEagle Crest Communities security record
52/100
DoxxScan™ · Elevated doxx risk
B- 75Above-average record

2 reported incidents on record.

See Eagle Crest Communities’s full breach history →
RelatedMore incidents at Eagle Crest Communities

More recent breaches

Bath Fitter Listed by anubis Ransomware GroupJuly 20, 2026Fairlife / Coca-Cola Listed by anubis Ransomware GroupJuly 20, 2026Bath Fitter Listed by anubis Ransomware GroupJuly 20, 2026Surtifamiliar Listed by anubis Ransomware GroupJuly 12, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the Eagle Crest Communities Listed by anubis Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by anubis — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram