LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › promises2kids.org Listed by qilin Ransomware Group

HIGH severityUnverified claimHow we verify

promises2kids.org Listed by qilin Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·June 24, 2024
promises2kids.org Listed by qilin Ransomware Group

Reported June 24, 2024.

HIGH
Severity
June 24, 2024
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The promises2kids.org Listed by qilin Ransomware Group (reported June 24, 2024) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
HIGH severityUnverified claim
Contact / identity PII exposed.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Ransomware groups continue to target nonprofits and social-service organizations that hold sensitive personal records, often listing victims on leak sites as part of double-extortion campaigns. In this environment, even smaller regional charities can appear on public claims of data theft, raising immediate questions for the people whose information those groups may hold.

On June 24, 2024, the ransomware group known as qilin listed promises2kids.org among its claimed victims. Public reporting states that internal files were exfiltrated in a ransomware attack. The number of people affected remains unknown, and further technical details have not been disclosed. The listing itself is a claim by the group rather than an independently confirmed disclosure.

Inside the incident

According to available public information, promises2kids.org was listed by the qilin ransomware group on June 24, 2024. The reported summary indicates that internal files were exfiltrated during a ransomware attack. No public figure has been given for the number of individuals affected, and the precise method of initial access, the duration of any intrusion, or the full scope of systems involved has not been disclosed. The only concrete assertion in the public record is the group’s claim that it obtained internal files and listed the organization. Without confirmation from the organization or independent forensic reporting, the listing remains an unverified claim of compromise and data theft.

Who is qilin?

Qilin is a ransomware operation that has been active for several years and is generally described as a ransomware-as-a-service group. Like many such actors, it is known for combining encryption of victim systems with the theft of data, then threatening to publish the stolen material if a ransom is not paid. The group maintains a leak site where it posts names of organizations it claims to have compromised, sometimes accompanied by sample files. Public reporting on prior campaigns has associated qilin with attacks across multiple sectors, including healthcare, manufacturing, and professional services. Its typical tactics include double extortion—demanding payment both to decrypt systems and to prevent release of stolen data—and the use of affiliates who carry out intrusions under the qilin brand. Nothing in the public record for this specific listing adds unique claims beyond the assertion that internal files from promises2kids.org were taken.

About promises2kids.org

Promises2Kids is a nonprofit organization that works with current and former foster youth in San Diego County. Public descriptions state that it annually provides more than 3,000 young people with tools, opportunities, and guidance intended to help them address the circumstances that led them into foster care and to navigate the challenges that follow. Organizations of this type typically maintain case notes, contact information, educational and mentoring records, and other personal data necessary to deliver services to vulnerable populations. Because foster-care systems already involve highly sensitive personal histories, any unauthorized access to an organization’s internal files carries elevated consequences for the individuals served. The sector as a whole has become a recurring target for ransomware groups precisely because the data held is difficult to replace and the organizations often operate with limited cybersecurity resources.

What was likely exposed

The only data type named in public reporting is “internal files” said to have been exfiltrated in the ransomware attack. No inventory of specific file categories, record counts, or data fields has been released. Organizations that support foster youth commonly hold names, dates of birth, addresses, contact details for youth and caregivers, case histories, educational records, and notes related to mentoring or support services. Whether any of those categories were among the files claimed by qilin is unconfirmed. Readers should treat the exact contents as unknown until the organization or independent investigators provide further detail.

Why it matters

For the young people and families connected to Promises2Kids, exposure of internal files could mean that personal histories, contact information, or service records become available to criminals. That information can be used for identity theft, targeted phishing, or social-engineering attempts that exploit knowledge of a person’s foster-care background. Even without confirmation of specific records, the mere claim of exfiltration creates lasting uncertainty for anyone who has interacted with the organization. For the nonprofit itself, a ransomware incident can disrupt service delivery, divert limited resources toward recovery and legal obligations, and erode the trust that is essential when working with vulnerable populations. The absence of a published count of affected individuals does not reduce the potential impact; it simply leaves those who may be affected without clear notice of what to monitor.

What to do if you're exposed

If you have ever been served by or worked with Promises2Kids, treat the possibility of exposure seriously even though the precise data set remains unconfirmed. Monitor financial accounts and credit reports for unexpected activity, and be alert to phishing messages that reference foster-care services or personal details. Consider placing a fraud alert or credit freeze with the major credit bureaus. Change passwords on any accounts that may have shared credentials with systems used by the organization, and enable multi-factor authentication wherever it is available. You can also run a free exposure scan of your email address to check whether your information has already appeared in known breach data sets. If you receive formal notification from the organization, follow the specific guidance it provides, including any offers of credit monitoring or identity-protection services.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

Companypromises2kids.org security record
88/100
DoxxScan™ · Low doxx risk
B 83Good record

1 reported incident on record.

See promises2kids.org’s full breach history →

More recent breaches

McCORMICK TAYLOR Listed by qilin Ransomware GroupDecember 29, 2024amourgis.com Listed by qilin Ransomware GroupDecember 25, 2024Access2Jobs Listed by qilin Ransomware GroupDecember 20, 2024Compliance Solutions Inc Listed by qilin Ransomware GroupDecember 17, 2024

Latest breaches

Read GalaxyWarden’s full analysis of the promises2kids.org Listed by qilin Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by qilin — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram