LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › EURORDIS Listed by qilin Ransomware Group

HIGH severityUnverified claimHow we verify

EURORDIS Listed by qilin Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·October 14, 2025
EURORDIS Listed by qilin Ransomware Group

Reported October 14, 2025.

HIGH
Severity
October 14, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

EURORDIS has been listed by the Qilin ransomware group, with internal files reported as exfiltrated. The listing came to light on October 14, 2025; anyone connected to the organisation should check their status and take appropriate protective steps.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Ransomware groups continue to target non-profits, advocacy bodies and health-adjacent organisations across Europe, treating the sensitive data they hold as leverage. In this climate of double-extortion attacks, even organisations focused on rare-disease support have appeared on criminal leak sites. On 14 October 2025, the ransomware group qilin publicly listed EURORDIS, claiming to have exfiltrated internal files. The number of people affected remains unknown, and public detail is limited, yet the listing alone raises clear concerns for anyone connected to the rare-disease community.

What is known is straightforward: EURORDIS was named on a qilin-associated site as the victim of a ransomware attack involving the theft of internal files. No further technical indicators, ransom demands or confirmation of data publication have been disclosed in the available record. The incident matters because EURORDIS works with patient organisations and individuals living with rare conditions—people whose personal and medical information is often highly sensitive.

Breaking down the breach

According to the reported facts, EURORDIS was listed by the qilin ransomware group on 14 October 2025. The group claims that internal files were exfiltrated during a ransomware attack. No figure for the number of people affected has been released; that number is simply unknown. The method of initial access, the duration of the intrusion, any encryption of systems, and whether a ransom was demanded or paid are all undisclosed. Public reporting does not confirm that the stolen files have been published or sold. The only concrete assertion available is the group’s own listing of the organisation and its statement that internal files were taken.

The group behind it: qilin

Qilin is a well-documented ransomware operation that has been active for several years. Like many modern groups, it typically operates on a ransomware-as-a-service model, providing affiliates with tools in exchange for a share of any proceeds. Its established pattern involves double extortion: encrypting systems while also stealing data and threatening to leak it if payment is not made. The group has previously claimed attacks against organisations in multiple sectors, including healthcare and professional services, and maintains a leak site where it posts victim names and, sometimes, sample data. In this case the listing of EURORDIS is a claim made by the group; it has not been independently verified in the public record, and no specific statements by qilin about the contents of EURORDIS files beyond the general assertion of internal-file exfiltration are available.

EURORDIS and its sector

EURORDIS is a European non-profit organisation dedicated to advocating for, empowering and engaging people affected by rare diseases. It works with patient organisations across the continent, provides information and support, and helps connect individuals and families who often face isolation and complex medical pathways. Organisations of this type routinely handle correspondence, membership or contact lists, project documents, and sometimes health-related or personal details shared by patients and carers. Because rare-disease communities are relatively small and tightly knit, a breach can affect people who already navigate significant medical and administrative burdens. The appearance of such an organisation on a ransomware leak site is therefore consequential both for the individuals it serves and for the trust that underpins patient advocacy work.

What was likely exposed

The facts state only that internal files were exfiltrated in a ransomware attack. Exact data types, file names, volumes and whether any personal or medical records were among them remain unconfirmed. Organisations such as EURORDIS typically hold a range of material that could include:

None of these categories has been verified as present in the stolen material. Public detail is limited to the group’s claim of internal-file exfiltration; readers should treat any more specific description as unconfirmed.

Why it matters

For people living with rare diseases, the possible exposure of contact details or health-related correspondence can create practical risks: unwanted contact, social-engineering attempts that exploit knowledge of a medical condition, or simply the distress of knowing personal information may be in criminal hands. For EURORDIS itself, the incident can disrupt operations, damage relationships with partner organisations, and require resources to investigate and respond. Even when the precise contents of stolen files are unknown, the mere listing by a ransomware group signals that sensitive organisational data may have left the organisation’s control. In the rare-disease sector, where trust and confidentiality are essential, that uncertainty carries weight for both the people served and the organisation that serves them.

If your data was in this claimed breach

If you have had contact with EURORDIS or related rare-disease networks, treat the possibility of exposure seriously even though the exact contents remain unconfirmed. Practical first steps include monitoring email accounts and financial statements for unusual activity, being cautious of unsolicited messages that reference rare-disease support or personal details, and enabling multi-factor authentication on important accounts where it is not already in place. Consider changing passwords for any accounts that may have been linked to communications with the organisation. Readers can also run a free exposure scan of their email address to check whether their information has already surfaced in known breach data sets. Stay alert to official updates from EURORDIS should further verified information become available.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyEURORDIS security record
84/100
DoxxScan™ · Low doxx risk
B- 76Above-average record

1 reported incident on record.

See EURORDIS’s full breach history →

More recent breaches

Francehopital Listed by qilin Ransomware GroupNovember 5, 2025Paris Rétina Vision Listed by qilin Ransomware GroupOctober 14, 2025PathoQuest-Biotechnology Research Listed by qilin Ransomware GroupSeptember 1, 2025radiologue.paris Listed by qilin Ransomware GroupMay 22, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the EURORDIS Listed by qilin Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by qilin — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram