Franciscan Friars of the Atonement Listed by dragonforce Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The Franciscan Friars of the Atonement Listed by dragonforce Ransomware Group (reported July 2, 2024) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
On 2 July 2024 the Franciscan Friars of the Atonement appeared on a listing published by the ransomware group known as dragonforce. The group claims that internal files belonging to the religious order were taken during a ransomware attack. For anyone whose name, contact details or other personal information may sit inside those files—donors, staff, volunteers, members of the community the Friars serve—the practical stakes are immediate: the risk that private records could be misused for fraud, identity theft or unwanted contact. Public detail remains limited; the number of people affected is unknown and the precise contents of the files have not been independently confirmed.
What follows is a careful account of what is known, what the listing claims, and what people who may be connected to the organisation can usefully do next.
Breaking down the breach
According to the available record, the Franciscan Friars of the Atonement were listed by dragonforce on 2 July 2024. The listing states that internal files were exfiltrated in a ransomware attack. No further technical details—such as the initial access method, the duration of the intrusion, the volume of data taken, or any ransom demand—have been disclosed in the public summary. The number of individuals whose information may be involved is recorded as unknown. Because the only source for the incident is the group’s own claim on its leak site, the assertion that a successful ransomware attack and data theft occurred remains unverified by independent reporting at the time of writing. Organisations in this position sometimes confirm or deny such claims later; no such confirmation appears in the facts provided here.
Inside dragonforce
Dragonforce is a ransomware operation that has been observed conducting double-extortion attacks: encrypting systems while also stealing data and threatening to publish it if a ransom is not paid. Like other groups of this type, it maintains a dark-web leak site where it posts the names of organisations it claims to have compromised, often accompanied by sample files or countdown timers. Public reporting on dragonforce has described it as operating a ransomware-as-a-service model in which affiliates carry out intrusions and share proceeds with the core operators. The group has previously listed victims across multiple sectors, using the threat of data exposure to increase pressure. In the present case the facts state only that the Franciscan Friars of the Atonement appear on the listing and that internal files are said to have been exfiltrated; no additional claims made by the group about this specific victim are recorded here, and none should be assumed.
Who is Franciscan Friars of the Atonement?
The Franciscan Friars of the Atonement is a Catholic religious community, also known as the Graymoor Friars, founded in the early twentieth century and based primarily in the United States. The order is engaged in pastoral work, ecumenical dialogue, retreats, and charitable outreach. Like most religious institutes of its kind, it maintains records of its members, employees, donors, retreat participants, and people who receive its services. Such organisations typically hold names, addresses, telephone numbers, email addresses, donation histories, and sometimes more sensitive pastoral or employment information. A breach involving an entity of this nature is consequential because the data often includes individuals who have placed a high degree of trust in the institution and who may not expect their personal details to circulate outside that relationship. The facts do not indicate the size of the order’s digital estate or the exact systems affected.
What was likely exposed
The only data type named in the available record is “internal files exfiltrated in ransomware attack.” No inventory of those files—whether they contain donor databases, personnel records, financial documents, correspondence, or other materials—has been published. Public detail on the precise contents is therefore unconfirmed. Organisations of this type commonly store contact information for supporters, membership and employment records, financial and donation data, and administrative documents. It is reasonable to expect that some combination of these categories could be present among internal files, yet it would be inaccurate to assert that any specific category was taken. Until the organisation itself or a verified forensic report provides a clearer description, the exact nature of the exposed material remains unknown.
The real-world impact
For individuals whose information may have been among the internal files, the concrete risks include phishing or social-engineering attempts that reference the Friars, fraudulent donation solicitations, and, in rarer cases, identity-related fraud if identifiers such as dates of birth or financial details were present. Because the number of people affected is unknown, the scale of any such risk cannot be quantified from the public record. For the organisation itself, the listing creates operational and reputational pressure: systems may need to be rebuilt or restored, donors and members may require notification and support, and regulatory or canonical reporting obligations may arise depending on jurisdiction. None of these outcomes is stated as fact in the available summary; they are the ordinary consequences that follow when a ransomware group claims to hold an organisation’s data.
If your data was in this claimed breach
If you have a past or present connection to the Franciscan Friars of the Atonement—as a donor, employee, volunteer, retreat participant or community member—treat the possibility of exposure seriously even while the details remain limited. Monitor bank and credit-card statements for unfamiliar activity, be cautious of unsolicited emails or calls that mention the Friars or request personal or financial information, and consider placing a fraud alert with credit-reporting agencies if you believe sensitive identifiers may have been involved. Change passwords on any accounts that reused credentials associated with the organisation. Readers can also run a free exposure scan of their email address to check whether that address has already appeared in known breach data sets; such a scan does not confirm or rule out involvement in this specific incident, but it can indicate whether the address is circulating more widely. Stay alert for any official notice from the Friars themselves, which would provide the most authoritative guidance once further facts become available.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Plan Listed by dragonforce Ransomware GroupLand and Lakes Listed by qilin Ransomware GroupAngotti & Reilly Listed by dragonforce Ransomware GroupWilliams Tank Lines Listed by dragonforce Ransomware GroupLatest breaches
Publicly posted by dragonforce — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.