LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › International AIDS Vaccine Initiative (iavi.org) Listed by incransom Ransomware Group

HIGH severityUnverified claimHow we verify

International AIDS Vaccine Initiative (iavi.org) Listed by incransom Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·January 27, 2025
International AIDS Vaccine Initiative (iavi.org) Listed by incransom Ransomware Group

Reported January 27, 2025.

HIGH
Severity
January 27, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

International AIDS Vaccine Initiative (iavi.org) appears on the listing published by the incransom ransomware group on January 27, 2025, with internal files reported as exfiltrated. The number of individuals affected remains undisclosed; anyone connected to the organization should review the incident notice and follow any recommended steps.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

On 27 January 2025 the International AIDS Vaccine Initiative, known publicly through iavi.org, appeared on a listing published by the ransomware group incransom. The group claims that internal files were taken in a ransomware attack. For staff, research partners, community participants in vaccine trials, and others whose details may sit inside IAVI systems, the practical question is straightforward: whether personal, professional or research-related information has left the organisation’s control and what that could mean for privacy and safety.

Public detail remains limited. The number of people affected is unknown, and no confirmed inventory of the files has been released by the organisation or independent investigators. What is known so far rests on the group’s claim and the basic description of the incident as a ransomware attack involving exfiltration of internal material.

What happened

According to the available record, the International AIDS Vaccine Initiative was listed by incransom on 27 January 2025. The listing characterises the incident as a ransomware attack in which internal files were allegedly exfiltrated. No further technical description of the intrusion method, the date the attack began, the volume of data taken, or any ransom demand has been made public in the facts at hand. The number of individuals whose information may be involved is listed as unknown. Because the primary source for the claim is the threat actor’s own leak-site entry, the assertion that data was stolen should be treated as an unverified claim until corroborated by the organisation or independent forensic reporting.

Ransomware incidents of this type typically involve encryption of systems combined with theft of files, followed by pressure to pay. In this case only the exfiltration of internal files is named; whether systems were encrypted, whether operations were disrupted, and whether any payment discussion occurred remain undisclosed.

The group behind it: incransom

Incransom is a ransomware operation that has appeared in public reporting as a group that conducts double-extortion attacks: encrypting victim systems while also copying data and threatening to publish it if a ransom is not paid. Like other actors in this category, the group maintains a leak site where it posts victim names and, in some cases, sample files or larger archives. Its listings function as both pressure and advertising. The group’s claims about any specific victim, including the volume or sensitivity of data, are self-serving and require independent verification.

Public knowledge of incransom’s broader activity shows a pattern of targeting organisations across sectors rather than a single industry focus. The group’s operational model relies on initial access—often through phishing, compromised credentials or unpatched systems—followed by lateral movement, data staging and encryption. None of those general tactics has been confirmed as the method used against IAVI; they are simply the established pattern associated with the actor. For this incident the only concrete assertion on record is the group’s claim that internal files belonging to the International AIDS Vaccine Initiative were exfiltrated.

About International AIDS Vaccine Initiative (iavi.org)

The International AIDS Vaccine Initiative is a global not-for-profit public-private partnership whose stated mission is to accelerate the development of vaccines to prevent HIV infection and AIDS. It researches and develops vaccine candidates, conducts policy analysis, advocates for the HIV-prevention field, and works with communities on trial processes and education. Organisations of this kind sit at the intersection of biomedical research, clinical-trial logistics, donor and partner relationships, and community engagement in regions heavily affected by HIV.

Because of that role, IAVI and similar entities routinely handle scientific data, administrative records, employee and contractor information, correspondence with research partners, and materials related to community outreach. A breach involving such an organisation is consequential not only for the individuals whose personal details may be present but also for the continuity of vaccine-development work and for the trust that trial participants and partner communities place in the institution. Public detail does not confirm which of these categories, if any, were among the files the group claims to have taken.

What data was at risk

The facts name only “internal files exfiltrated in a ransomware attack.” No further breakdown—such as employee records, research datasets, financial documents, or trial-related materials—has been disclosed. The number of people affected is unknown. Organisations engaged in HIV-vaccine research and community engagement typically maintain a range of information: personnel files, partner contracts, scientific notes, correspondence, and sometimes de-identified or carefully controlled participant data. Whether any of those categories were present in the material claimed by incransom is unconfirmed.

Until an official inventory or independent analysis is published, the precise contents of the exfiltrated files remain unknown. Readers should treat any specific assertion about data types beyond the phrase “internal files” as unverified.

The real-world impact

For individuals whose information may have been among the internal files, the concrete risks are the ordinary ones associated with data exposure: possible misuse of contact details, credentials or personal identifiers for phishing, social engineering or identity fraud. Because the exact data types are undisclosed, the severity for any given person cannot yet be assessed. Staff and contractors may face elevated risk of targeted follow-on messages that appear to come from IAVI or its partners. Research collaborators could see sensitive correspondence or proprietary notes surface, creating professional and competitive concerns.

For the organisation itself the impact includes potential operational disruption, the cost of investigation and remediation, and the harder-to-measure effect on trust among communities that participate in HIV-prevention research. Vaccine-development work depends on long-term relationships with trial sites and participants; any perception that data handling has been compromised can slow recruitment or cooperation even when the scientific programmes continue. None of these outcomes is confirmed as having already materialised; they are the realistic consequences that follow from a ransomware claim of this nature when internal files are said to have left the organisation’s control.

Were you affected?

If you have ever been an employee, contractor, research partner, donor contact or community participant connected with the International AIDS Vaccine Initiative, treat the listing as a reason to take ordinary precautions rather than as proof that your specific data was taken. Public confirmation of who is affected has not been issued.

Further verified information, if released by the organisation or by independent investigators, will be the most reliable basis for deciding what additional steps are necessary. Until then, the prudent course is heightened vigilance without assuming the worst about data that has not been publicly detailed.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyInternational AIDS Vaccine Initiative security record
87/100
DoxxScan™ · Low doxx risk
B 80Good record

1 reported incident on record.

See International AIDS Vaccine Initiative’s full breach history →

More recent breaches

West Texas Oral and Facial Surgery Listed by incransom Ransomware GroupJune 17, 2025Academic Urology & Urogynecology of Arizona Listed by incransom Ransomware GroupJune 17, 2025Essex County OB/GYN Associates Listed by incransom Ransomware GroupMarch 11, 2025Colorado Rehabilitation & Occupational Medicine Claimed by IncRansomJuly 2, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the International AIDS Vaccine Initiative (iavi.org) Listed by incransom Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by incransom — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram