Regina Coeli Convent Listed by incransom Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Regina Coeli Convent was listed by the incransom ransomware group on January 17, 2025, after internal files were exfiltrated in an attack whose exact date remains unknown. Individuals connected to the convent should review any notifications and monitor their personal information for signs of misuse.
On January 17, 2025, Regina Coeli Convent was listed by the ransomware group known as incransom, which claimed to have carried out an attack involving the exfiltration of internal files. Public detail on the incident remains limited: the number of people affected is unknown, and no further confirmation of the group's claims has been reported.
The listing matters because Regina Coeli Convent operates early childhood services for more than 1,800 children and employs more than 500 people across a five-parish area. Any compromise of internal files at an organization of this type can place sensitive operational and personal information at risk for families, staff, and the wider community it serves.
Inside the incident
According to the available record, Regina Coeli Convent was listed by the incransom ransomware group on January 17, 2025. The group claims that internal files were exfiltrated in a ransomware attack. No public information has been released about the precise timing of the intrusion, the method used to gain access, the volume of data taken, or whether systems were encrypted. The number of individuals potentially affected is listed as unknown. Beyond the leak-site listing itself, no independent verification of the claims has been provided in the reported facts.
As with many ransomware listings, the appearance of an organization's name on a threat actor's site constitutes a claim rather than a fully confirmed disclosure. Organizations in this position typically investigate, contain any intrusion, and assess what, if anything, left their network. Those steps and their outcomes have not been detailed in the public record for this incident.
Who is incransom?
Incransom is a ransomware operation that follows a model common among contemporary groups: operators gain unauthorized access to a victim's network, exfiltrate data, and then demand payment under threat of publishing the stolen material on a dedicated leak site. The group has been observed listing organizations across multiple sectors, using the public naming of victims as leverage. Like other ransomware actors, incransom typically claims responsibility for both encryption and data theft, though the accuracy of any single claim must be treated as unverified until corroborated by the victim or independent investigation.
Public reporting on the group has described the usual tactics of initial access through common vectors such as phishing or exploitation of exposed services, followed by lateral movement and data staging. No specific technical details of the alleged attack on Regina Coeli Convent have been released, so nothing beyond the group's general pattern can be stated about this particular case. The listing of the convent is therefore best understood as an assertion by the group rather than an established fact of confirmed compromise.
About Regina Coeli Convent
Regina Coeli Convent provides high-quality, comprehensive early childhood services. Its own description states that it serves over 1,800 children and employs over 500 people in a five-parish area. The organization's stated mission is to deliver the highest quality of service to children and families through a community team effort guided by the question: "Is it good for children?"
Entities of this kind typically operate as faith-based or community-linked providers of preschool, daycare, and related family support programs. They maintain records necessary for enrollment, health and safety compliance, staffing, and funding. Because they work closely with young children and their families, they hold information that is both operationally sensitive and personally identifiable. A ransomware incident affecting such an organization therefore carries implications that extend beyond ordinary business disruption into the privacy and security of the households it serves.
What data was at risk
The reported facts state only that internal files were exfiltrated in a ransomware attack. No inventory of specific data categories, file counts, or record types has been disclosed. Exact contents therefore remain unconfirmed.
Organizations that deliver early childhood services commonly hold enrollment forms, contact details for parents and guardians, health and immunization records, staff employment files, financial and payroll data, and internal administrative documents. Whether any of these categories were among the files claimed by incransom is not known from the public record. Until the organization or an independent investigation releases further detail, the precise nature of the exposed material cannot be stated as fact.
What's at stake
For families, the primary concern is the potential exposure of personal information belonging to children and parents. Even without confirmed data types, the possibility that contact details, health information, or family circumstances could have left the network creates ongoing risks of phishing, identity misuse, or unwanted contact. Staff members face similar exposure of employment and personal data.
For the organization itself, a ransomware incident can interrupt service delivery, impose recovery costs, and damage trust among the families and parishes it serves. Because the number of people affected remains unknown and the full scope of the exfiltration is undisclosed, the concrete scale of harm cannot yet be measured. The practical stakes are therefore those of uncertainty: the need to determine what left the environment, to notify anyone whose information may have been involved, and to restore secure operations without further compromise.
If your data was in this claimed breach
If you are a parent, guardian, staff member, or other individual connected to Regina Coeli Convent, treat the listing as a reason for caution rather than confirmed personal exposure. Monitor financial and email accounts for unusual activity, be alert to unexpected messages that reference the organization or request personal details, and consider placing fraud alerts with credit bureaus if you believe sensitive identifiers may have been involved. Change passwords on any accounts that reused credentials associated with the organization, and enable multi-factor authentication where available.
Because the exact data involved has not been confirmed, the most useful immediate step is to verify whether your own email address has already appeared in known breach collections. Free exposure-scan tools can check that address against publicly documented breach data and provide a starting point for further personal monitoring. Stay attentive to any official notices the organization may issue as its investigation proceeds.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
WSI Listed by incransom Ransomware Groupshawhillprimaryschool.org.uk Listed by incransom Ransomware Groupstignatiusijamsville.org Listed by incransom Ransomware Groupbennett.edu Listed by incransom Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Regina Coeli Convent Listed by incransom Ransomware Group →
Publicly posted by incransom — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.