katholiekamersfoort.nl Listed by stormous Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
katholiekamersfoort.nl has been listed by the stormous ransomware group, with internal files reported to have been exfiltrated. The breach was disclosed on June 02, 2026; anyone connected to the organisation should verify whether their information was exposed and take appropriate protective steps.
On June 2, 2026, the ransomware group Stormous listed katholiekamersfoort.nl on its data-leak site, claiming to have breached the network of the Dutch Catholic church website and removed more than 10 GB of internal files. The listing states that the exfiltrated material relates to donors, staff, and a large number of other individuals, but independent confirmation of the incident or its scope has not been made public.
Such listings have become a routine feature of the current ransomware landscape, where groups combine encryption with data theft and then use public claims to pressure victims. The katholiekamersfoort.nl case illustrates how even modest-sized religious organisations now appear in these disclosures, raising questions about the handling of personal records that extend beyond the immediate operational impact.
Inside the incident
The only confirmed public information is the June 2, 2026 listing itself. Stormous asserts that it obtained internal files through a ransomware operation and that the material exceeds 10 GB. No official statement from the organisation, no law-enforcement bulletin, and no independent forensic report have been released, so the precise date of the intrusion, the method of initial access, and the number of individuals whose information was taken remain undisclosed.
Who is stormous?
Stormous is a ransomware group that has operated publicly since at least 2022. It follows the now-common pattern of encrypting victim systems, copying selected files, and then posting victim names on a dedicated leak site when ransom negotiations fail or stall. The group has previously claimed activity against targets in multiple sectors and countries, though the accuracy of individual claims varies and is rarely verified by third parties at the time of posting.
Who is katholiekamersfoort.nl?
Katholiekamersfoort.nl is the public website of a Catholic parish or diocesan organisation based in Amersfoort, the Netherlands. Like many religious bodies, it maintains records on members, volunteers, donors, and staff to support pastoral care, financial administration, and governance. These records frequently contain contact details, contribution histories, and internal correspondence that are not otherwise available to the public.
What data was at risk
According to the listing, the exfiltrated material includes databases and personally identifiable information, internal network shares and documents, contact lists, board and committee data, and system metadata. The exact contents of these files have not been independently verified, and the organisation has not published an inventory of the compromised records.
Why it matters
Personal data held by religious organisations can include sensitive details about individuals’ affiliations, financial contributions, and family circumstances. When such information is removed from its original environment, affected people face the possibility of unwanted contact, fraud, or reputational exposure. For the organisation, the incident adds administrative burden, potential regulatory scrutiny under European data-protection rules, and the need to review long-term data-retention practices.
Were you affected?
Individuals who have interacted with katholiekamersfoort.nl as donors, volunteers, or parishioners have no confirmed way to determine exposure from public sources alone. The first practical step is to monitor official communications from the organisation. Separately, anyone can run a free exposure scan of their email address against known breach data sets to check whether their information has appeared in previously published leaks.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Official Statement: Protecting palatineschool.org Infrastructure Listed by stormous Ransomware GroupBN: higuchi-inc Report Error & Warning Listed by stormous Ransomware GroupOfficial Statement Listed by stormous Ransomware Groupeogb.co.uk Listed by stormous Ransomware GroupLatest breaches
Publicly posted by stormous — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.