ourrelentlesschurch.com Listed by lockbit3 Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The ourrelentlesschurch.com Listed by lockbit3 Ransomware Group (reported April 29, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
Ransomware groups have continued to target organisations of every size and sector, including nonprofits and faith communities that hold personal and operational records. In that broader pattern, a listing associated with ourrelentlesschurch.com appeared on a lockbit3 leak site in late April 2023, drawing attention to a claimed ransomware incident involving internal files.
Public detail on the event remains limited. What is known is that the organisation was named by the group, that the reported date is April 29, 2023, and that the claim centres on exfiltration of internal files. The number of people affected has not been disclosed. For anyone connected to the church—members, staff, volunteers, or partners—understanding the claim and the ordinary risks that follow is a practical step, not a cause for alarm.
Breaking down the breach
According to available reporting, ourrelentlesschurch.com was listed by the lockbit3 ransomware group on or about April 29, 2023. The group’s claim describes internal files exfiltrated in a ransomware attack. No confirmed figure for the number of people affected has been published, and public sources do not detail the precise method of initial access, the duration of any intrusion, or whether systems were encrypted in addition to data being taken.
Because the primary public signal is a leak-site listing, the incident should be treated as an unverified claim by the threat actor unless and until the organisation or independent investigators confirm further specifics. Timing beyond the reported date, the scale of any data set, and technical indicators of compromise remain undisclosed in the material at hand. In short, the known facts are narrow: a named organisation, a named ransomware brand, a reported date, and a description limited to internal files said to have been exfiltrated.
Inside lockbit3
LockBit3 is a well-documented ransomware operation that has, over several years, run a prominent affiliate model. In that model, operators provide the ransomware and leak infrastructure while affiliates conduct intrusions, often using stolen credentials, exploited vulnerabilities, or phishing to gain a foothold. Once inside a network, actors typically move laterally, steal data, and deploy encryption, then pressure victims with the threat of publishing stolen material on a dedicated leak site if a ransom is not paid.
The group has been associated with attacks across many industries and geographies. Its public leak sites have been used to name alleged victims and, in some cases, to release sample files or larger archives. Those listings are claims by the group; they are not independent confirmation that every named organisation was successfully breached to the extent advertised, nor do they automatically prove the full contents of any alleged archive. In this instance, lockbit3’s listing of ourrelentlesschurch.com should be read in that light: the group claims the organisation was hit and that internal files were taken. No further statements by the group about this specific victim are part of the provided facts.
Who is ourrelentlesschurch.com?
Relentless Church, associated with the domain ourrelentlesschurch.com, describes its purpose as sharing the news of Jesus Christ, discipling people, and building the whole person—mind, body, and soul. Churches and similar faith organisations typically operate as community hubs. They often maintain membership or attendance records, volunteer and staff information, event and ministry schedules, donation and giving histories, pastoral or counselling notes in some cases, and ordinary business records such as vendor contracts, email, and internal documents.
A breach claim against such an organisation matters because the data held is frequently personal and relational rather than purely commercial. Congregants and staff may have shared contact details, family information, financial giving records, or sensitive pastoral communications in trust. Even when the exact contents of a claimed exfiltration are unknown, the sector context explains why listings of churches draw concern: the potential exposure touches people’s private lives and the institution’s ability to operate and maintain confidence.
What data was at risk
The facts name the exposed material only as internal files exfiltrated in a ransomware attack. No inventory of file types, no count of records, and no confirmation of specific categories such as donor lists, membership databases, or employee records have been disclosed in the material provided.
Organisations of this kind commonly hold names, addresses, phone numbers, email addresses, donation or tithe records, volunteer schedules, staff personnel files, and internal correspondence. Some also store more sensitive pastoral or counselling-related notes. None of those categories should be stated as confirmed contents of this incident. The exact data at risk remains unconfirmed; only the broad description “internal files” is given. Readers should treat any more detailed claim about what was taken as unverified until corroborated by the organisation or reputable incident reporting.
What's at stake
For individuals, the practical risks of internal church files appearing in a ransomware leak can include unwanted contact, phishing that impersonates church staff or ministries, and misuse of personal or financial details if such details were present. Donation histories or membership data, if exposed, can help criminals craft convincing scams. Even routine contact information can be combined with other breaches to increase fraud risk. Emotional and reputational harm is also possible if private communications or sensitive pastoral matters were among any taken files—though again, that content is not confirmed here.
For the organisation, stakes include operational disruption, the cost of investigation and recovery, potential notification duties where applicable, and erosion of trust among members and partners. Ransomware incidents can also divert leadership attention from ministry work for extended periods. None of this establishes negligence; it simply describes the ordinary consequences that follow when a threat actor claims to hold an institution’s internal data.
Were you affected?
If you have been connected to Relentless Church as a member, donor, volunteer, or staff member, treat the lockbit3 claim as a reason for ordinary caution rather than panic. Monitor financial and email accounts for unusual activity, be wary of unexpected messages that reference the church or ask for credentials or payments, and consider updating passwords on important accounts—especially if you reused a password tied to church-related services. Prefer unique passwords and multi-factor authentication where available.
Public detail on who, if anyone, had personal data included remains unknown. You can run a free exposure scan of your email address to check whether your information has already surfaced in known breach data sets, and you can follow any official guidance the organisation may issue if it confirms more about the incident. Staying alert to phishing and keeping personal records current are sensible steps while the full scope stays undisclosed.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
aldoshoes.com Listed by lockbit3 Ransomware Groupnckb.com Listed by lockbit3 Ransomware Groupdistribuidoradavidsa.com Listed by lockbit3 Ransomware Groupmergerecords.com Listed by lockbit3 Ransomware GroupLatest breaches
Publicly posted by lockbit — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.