LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › ourrelentlesschurch.com Listed by lockbit3 Ransomware Group

HIGH severityUnverified claimHow we verify

ourrelentlesschurch.com Listed by lockbit3 Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·April 29, 2023
ourrelentlesschurch.com Listed by lockbit3 Ransomware Group

Reported April 29, 2023.

HIGH
Severity
April 29, 2023
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The ourrelentlesschurch.com Listed by lockbit3 Ransomware Group (reported April 29, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Ransomware groups have continued to target organisations of every size and sector, including nonprofits and faith communities that hold personal and operational records. In that broader pattern, a listing associated with ourrelentlesschurch.com appeared on a lockbit3 leak site in late April 2023, drawing attention to a claimed ransomware incident involving internal files.

Public detail on the event remains limited. What is known is that the organisation was named by the group, that the reported date is April 29, 2023, and that the claim centres on exfiltration of internal files. The number of people affected has not been disclosed. For anyone connected to the church—members, staff, volunteers, or partners—understanding the claim and the ordinary risks that follow is a practical step, not a cause for alarm.

Breaking down the breach

According to available reporting, ourrelentlesschurch.com was listed by the lockbit3 ransomware group on or about April 29, 2023. The group’s claim describes internal files exfiltrated in a ransomware attack. No confirmed figure for the number of people affected has been published, and public sources do not detail the precise method of initial access, the duration of any intrusion, or whether systems were encrypted in addition to data being taken.

Because the primary public signal is a leak-site listing, the incident should be treated as an unverified claim by the threat actor unless and until the organisation or independent investigators confirm further specifics. Timing beyond the reported date, the scale of any data set, and technical indicators of compromise remain undisclosed in the material at hand. In short, the known facts are narrow: a named organisation, a named ransomware brand, a reported date, and a description limited to internal files said to have been exfiltrated.

Inside lockbit3

LockBit3 is a well-documented ransomware operation that has, over several years, run a prominent affiliate model. In that model, operators provide the ransomware and leak infrastructure while affiliates conduct intrusions, often using stolen credentials, exploited vulnerabilities, or phishing to gain a foothold. Once inside a network, actors typically move laterally, steal data, and deploy encryption, then pressure victims with the threat of publishing stolen material on a dedicated leak site if a ransom is not paid.

The group has been associated with attacks across many industries and geographies. Its public leak sites have been used to name alleged victims and, in some cases, to release sample files or larger archives. Those listings are claims by the group; they are not independent confirmation that every named organisation was successfully breached to the extent advertised, nor do they automatically prove the full contents of any alleged archive. In this instance, lockbit3’s listing of ourrelentlesschurch.com should be read in that light: the group claims the organisation was hit and that internal files were taken. No further statements by the group about this specific victim are part of the provided facts.

Who is ourrelentlesschurch.com?

Relentless Church, associated with the domain ourrelentlesschurch.com, describes its purpose as sharing the news of Jesus Christ, discipling people, and building the whole person—mind, body, and soul. Churches and similar faith organisations typically operate as community hubs. They often maintain membership or attendance records, volunteer and staff information, event and ministry schedules, donation and giving histories, pastoral or counselling notes in some cases, and ordinary business records such as vendor contracts, email, and internal documents.

A breach claim against such an organisation matters because the data held is frequently personal and relational rather than purely commercial. Congregants and staff may have shared contact details, family information, financial giving records, or sensitive pastoral communications in trust. Even when the exact contents of a claimed exfiltration are unknown, the sector context explains why listings of churches draw concern: the potential exposure touches people’s private lives and the institution’s ability to operate and maintain confidence.

What data was at risk

The facts name the exposed material only as internal files exfiltrated in a ransomware attack. No inventory of file types, no count of records, and no confirmation of specific categories such as donor lists, membership databases, or employee records have been disclosed in the material provided.

Organisations of this kind commonly hold names, addresses, phone numbers, email addresses, donation or tithe records, volunteer schedules, staff personnel files, and internal correspondence. Some also store more sensitive pastoral or counselling-related notes. None of those categories should be stated as confirmed contents of this incident. The exact data at risk remains unconfirmed; only the broad description “internal files” is given. Readers should treat any more detailed claim about what was taken as unverified until corroborated by the organisation or reputable incident reporting.

What's at stake

For individuals, the practical risks of internal church files appearing in a ransomware leak can include unwanted contact, phishing that impersonates church staff or ministries, and misuse of personal or financial details if such details were present. Donation histories or membership data, if exposed, can help criminals craft convincing scams. Even routine contact information can be combined with other breaches to increase fraud risk. Emotional and reputational harm is also possible if private communications or sensitive pastoral matters were among any taken files—though again, that content is not confirmed here.

For the organisation, stakes include operational disruption, the cost of investigation and recovery, potential notification duties where applicable, and erosion of trust among members and partners. Ransomware incidents can also divert leadership attention from ministry work for extended periods. None of this establishes negligence; it simply describes the ordinary consequences that follow when a threat actor claims to hold an institution’s internal data.

Were you affected?

If you have been connected to Relentless Church as a member, donor, volunteer, or staff member, treat the lockbit3 claim as a reason for ordinary caution rather than panic. Monitor financial and email accounts for unusual activity, be wary of unexpected messages that reference the church or ask for credentials or payments, and consider updating passwords on important accounts—especially if you reused a password tied to church-related services. Prefer unique passwords and multi-factor authentication where available.

Public detail on who, if anyone, had personal data included remains unknown. You can run a free exposure scan of your email address to check whether your information has already surfaced in known breach data sets, and you can follow any official guidance the organisation may issue if it confirms more about the incident. Staying alert to phishing and keeping personal records current are sensible steps while the full scope stays undisclosed.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

Companyourrelentlesschurch.com security record
88/100
DoxxScan™ · Low doxx risk
B 83Good record

1 reported incident on record.

See ourrelentlesschurch.com’s full breach history →

More recent breaches

aldoshoes.com Listed by lockbit3 Ransomware GroupDecember 5, 2023nckb.com Listed by lockbit3 Ransomware GroupNovember 5, 2023distribuidoradavidsa.com Listed by lockbit3 Ransomware GroupAugust 29, 2023mergerecords.com Listed by lockbit3 Ransomware GroupAugust 29, 2023

Latest breaches

Read GalaxyWarden’s full analysis of the ourrelentlesschurch.com Listed by lockbit3 Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by lockbit — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram