LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › franklin nursing home Listed by incransom Ransomware Group

HIGH severityUnverified claimHow we verify

franklin nursing home Listed by incransom Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·April 22, 2025
franklin nursing home Listed by incransom Ransomware Group

Reported April 22, 2025.

HIGH
Severity
April 22, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Franklin Nursing Home has been listed by the Incransom ransomware group, with internal files reported exfiltrated in the attack. The incident was disclosed on 22 April 2025, and anyone connected to the organisation should check for notifications and follow any recommended steps.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Franklin Nursing Home was listed by the incransom ransomware group on or around April 22, 2025, according to public reporting of the group's leak-site claim. The listing asserts that internal files were exfiltrated in a ransomware attack. The number of people affected remains unknown, and no further Reported Details about the intrusion method, timeline, or full scope have been disclosed.

This matters because Franklin Nursing Home provides residential care for older adults, including feeding residents and monitoring their treatment. Any compromise of its systems can place sensitive personal and health-related information at risk, even when exact contents of the stolen files stay unconfirmed.

Inside the incident

Public information is limited to the incransom group's claim that it listed Franklin Nursing Home after a ransomware attack in which internal files were exfiltrated. The report date associated with the listing is April 22, 2025. No official confirmation of the breach by the organisation itself, no disclosed count of affected individuals, and no description of the initial access vector, encryption status, or ransom demand appear in the available facts. Scale and technical method therefore remain undisclosed.

Ransomware incidents of this type typically involve unauthorised access followed by data theft and, in many cases, encryption of systems. Here the only concrete assertion is the group's statement that internal files were taken. Whether systems were encrypted, whether a ransom was paid, or whether the data has been published beyond the listing is not stated in the record.

Who is incransom?

Incransom is a ransomware group that operates under a double-extortion model common among contemporary threat actors. Groups of this kind typically gain access to a victim network, exfiltrate data, encrypt systems, and then threaten to publish the stolen material on a dedicated leak site if payment is not made. They often list claimed victims publicly to increase pressure.

Incransom has been observed targeting organisations across multiple sectors. Its public listings serve as claims rather than independently Reported Facts; the appearance of a name on such a site indicates the group asserts it holds data from that organisation. No additional statements by incransom specifically detailing the Franklin Nursing Home incident beyond the listing itself are recorded in the available facts.

franklin nursing home and its sector

Franklin Nursing Home is a care facility that looks after older people, provides meals, and monitors residents' treatment. Organisations in the nursing-home and long-term-care sector routinely handle large volumes of personal, medical, and administrative information. This includes resident identities, health histories, medication records, family contact details, billing data, and staff records.

A breach in this sector is consequential because residents are often elderly and may be less able to monitor or respond quickly to identity or financial misuse. Care providers also hold data that can be used for fraud, social-engineering attacks against families, or further targeting of vulnerable individuals. Even when the precise files taken remain unconfirmed, the nature of the services creates elevated sensitivity around any unauthorised access.

What was likely exposed

The facts state that internal files were exfiltrated in the ransomware attack. Exact data types beyond that description are not disclosed. Organisations of this kind typically hold the following categories of information, though it is unconfirmed whether any specific items were among the files taken:

Because the precise contents remain unconfirmed, no definitive inventory of exposed data can be stated.

The real-world impact

For residents and their families, the primary risks include potential misuse of personal and health information for identity theft, targeted phishing, or fraudulent claims. Medical details can be especially sensitive and may cause distress if published or sold. Staff whose data may have been included face similar exposure risks.

For the organisation, consequences can include operational disruption if systems were encrypted, regulatory scrutiny under health-privacy rules, reputational damage, and the cost of investigation and remediation. Because the number of people affected is unknown and the full data set is undisclosed, the precise scale of harm cannot yet be measured. The listing itself already places the facility under public scrutiny.

If your data was in this claimed breach

If you or a family member have been associated with Franklin Nursing Home, treat the possibility of exposure seriously even while details remain limited. Monitor financial accounts and credit reports for unusual activity. Be alert to unexpected communications that reference the facility or claim to offer help related to a breach. Consider placing fraud alerts with credit bureaus if you believe sensitive identifiers may have been involved. Change passwords on any accounts that reused credentials connected to the organisation, and enable multi-factor authentication wherever available. Readers can also run a free exposure scan of their email address to check whether their information has already surfaced in known breach data sets. Official notifications, if issued by the facility or regulators, should be followed carefully for any additional steps specific to this incident.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

Companyfranklin nursing home security record
87/100
DoxxScan™ · Low doxx risk
B 80Good record

1 reported incident on record.

See franklin nursing home’s full breach history →

More recent breaches

www.precipiodx.com Listed by incransom Ransomware GroupDecember 2, 2025forensicmed.com Listed by incransom Ransomware GroupNovember 12, 2025sensationalteeth.com Listed by incransom Ransomware GroupOctober 5, 2025suntreeinternalmedicine.com Listed by incransom Ransomware GroupOctober 1, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the franklin nursing home Listed by incransom Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by incransom — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram