National Association of Eating Disorders Listed by revil Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The National Association of Eating Disorders Listed by revil Ransomware Group (reported April 1, 2020) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
What happened
The National Association of Eating Disorders was listed on the revil ransomware group's leak site on April 1, 2020. The group claims to have stolen internal data from the organization during a ransomware attack. The number of people affected remains unknown, and no further details on the scale or method of the intrusion have been publicly confirmed beyond the listing itself.
The group behind it: revil
REvil, also known as Sodinokibi, operated as a ransomware-as-a-service group that developed and distributed encryption malware to affiliate attackers. The group was publicly known for combining file encryption with the threat of data publication on dedicated leak sites, a tactic used to pressure victims into paying ransoms. Prior to its disruption by law enforcement actions in 2021, REvil had claimed responsibility for intrusions at numerous organizations across multiple sectors.
National Association of Eating Disorders and its sector
The National Association of Eating Disorders functions as a nonprofit focused on support, education, and resources related to eating disorders. Organizations in this sector routinely collect and store personal health information, contact details, and records from individuals seeking assistance or participating in programs. A breach at such an entity can affect people already navigating sensitive medical or psychological circumstances.
What was likely exposed
The available information states that internal files were exfiltrated. No specific categories of data or volume of records have been confirmed in public reports. Organizations of this type commonly hold contact information, health-related details, and administrative records, though the precise contents of the claimed exfiltration remain unconfirmed.
The real-world impact
Individuals whose information appears in the exposed files could encounter risks such as unauthorized access to personal health details or targeted scams. The organization itself may face operational disruption, reputational strain, and costs associated with response and recovery. Because the affected population size is unknown, the full scope of these consequences cannot yet be measured.
If your data was in this claimed breach
Monitor accounts linked to any email addresses or identifiers you used with the organization and enable multi-factor authentication where available. Review statements from the National Association of Eating Disorders for any official notifications. Readers can run a free exposure scan of their email address against known breach data to check for appearances in public listings.
- Change passwords for any associated accounts.
- Watch for unusual activity in financial or medical records.
- Contact the organization directly for updates on its response.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Beacon Health Solutions Listed by revil Ransomware GroupAAA Ambulance Service Listed by revil Ransomware GroupCrozer-Keystone Health System (Delaware County, PA) Listed by revil Ransomware GroupUniversity Medical Center Listed by revil Ransomware GroupLatest breaches
Publicly posted by revil — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.