I&Y Senior Care Listed by losttrust Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The I&Y Senior Care Listed by losttrust Ransomware Group (reported September 26, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
Ransomware groups continue to target healthcare and home-care providers, drawn by the sensitive personal and medical information these organisations hold and by the operational pressure that can follow disruption. In this landscape, listings on criminal leak sites have become a common way for attackers to publicise claims and apply leverage. One such listing, reported on 26 September 2023, named I&Y Senior Care as a victim of the group known as losttrust.
Public detail on the incident remains limited. What is known is that losttrust claimed to have carried out a ransomware attack involving the exfiltration of internal files. The number of people affected has not been disclosed, and independent confirmation of the full scope has not been made public. For clients, families, and staff connected to a senior-care agency, even an unverified claim warrants careful attention because of the kinds of data such organisations typically manage.
What happened
According to reporting dated 26 September 2023, I&Y Senior Care was listed by the losttrust ransomware group. The group’s claim centres on a ransomware attack in which internal files were exfiltrated. No public figure has been given for the number of individuals affected, and specifics about the timing of the intrusion, the initial access method, or the precise volume of data taken have not been disclosed in the available record. The listing itself constitutes the group’s assertion; it has not been independently verified in the facts provided here. Organisations facing such claims sometimes negotiate, restore from backups, or both; none of those outcomes is confirmed in this case.
The group behind it: losttrust
Losttrust is a ransomware operation that has appeared in public reporting as a double-extortion actor: it encrypts systems and simultaneously steals data, then threatens to publish the stolen material if payment is not made. Like other groups in this category, it has used dedicated leak sites to name alleged victims and, in some cases, to release sample files as proof. Its activity has been tracked across multiple sectors; healthcare and care-related organisations have featured among the types of entities it has claimed. Tactics commonly associated with such groups include phishing, exploitation of exposed remote-access services, and the use of commodity or custom ransomware payloads, though the exact technique used against any single victim is rarely confirmed without forensic disclosure. In this instance, the only specific claim tied to I&Y Senior Care is the leak-site listing and the assertion that internal files were exfiltrated. No further statements attributed to losttrust about this particular organisation appear in the given facts.
Who is I&Y Senior Care?
I&Y Senior Care is described as an agency that supplies qualified and paraprofessional caregivers working under the supervision of the agency’s registered nurse. Its services include home health aides and personal care aides, offered on an hourly basis as well as 24-hour live-in arrangements. Organisations of this kind sit at the intersection of healthcare support and in-home assistance for older adults and others who need help with daily living. They routinely handle scheduling, care plans, staff credentials, and communications with clients and families. Because care is delivered in private homes and often involves vulnerable individuals, the operational and personal data such agencies maintain can be especially sensitive. A ransomware incident affecting an entity in this sector therefore raises concerns not only about business continuity but also about the privacy and safety of the people who rely on those services.
The information in question
The available facts state that internal files were exfiltrated in a ransomware attack. No further breakdown of data types—such as names, contact details, medical notes, Social Security numbers, financial records, or employee information—has been publicly named. Exact contents therefore remain unconfirmed. In general, senior-care and home-health agencies typically hold client demographic and contact information, care assessments and plans, medication or health-status notes, insurance or billing data, and records relating to aides and other staff (credentials, schedules, and sometimes background-check material). Whether any of those categories were among the files losttrust claims to have taken is not established in the public record. Readers should treat the exposure as a possibility rather than a confirmed inventory of specific fields.
Why it matters
For individuals who receive or arrange care through an agency like I&Y Senior Care, the practical risks of a data exposure include identity theft, targeted phishing that impersonates the agency or a caregiver, and the misuse of health-related or household details. Older adults and their families can be particularly susceptible to follow-on scams that reference real care relationships. Staff whose employment or credential information may have been involved face similar identity and fraud risks. For the organisation, a ransomware event can interrupt scheduling and care delivery, create regulatory notification obligations, and erode trust among clients and referral partners. Even when the precise data set is unknown, the combination of a claimed exfiltration and the sensitive nature of home-care work makes prudent monitoring and basic protective steps advisable for anyone who has had a relationship with the agency.
Were you affected?
If you or a family member have used I&Y Senior Care services, or if you have worked for the agency, consider practical steps: monitor financial and medical accounts for unusual activity; be cautious of unexpected calls, emails, or messages that reference your care arrangements or personal details; and place fraud alerts or credit freezes if you believe sensitive identifiers may have been involved. Because the number of people affected and the exact data types remain undisclosed, there is no public list to check against. You can run a free exposure scan of your email address to see whether it has appeared in known breach data sets elsewhere; that check does not confirm or rule out involvement in this specific incident, but it can highlight other exposures that deserve attention. Stay alert to official notices from the agency or regulators, and rely on verified channels rather than unsolicited contacts claiming to help with the breach.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
GI Medical Services Listed by losttrust Ransomware GroupAmbrosini Holding Listed by losttrust Ransomware GroupPopovici Niu Stoica & Asociaii Listed by losttrust Ransomware GroupOasys Technologies Listed by losttrust Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the I&Y Senior Care Listed by losttrust Ransomware Group →
Publicly posted by losttrust — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.