The Holiday:Adult Care Community & Retirement Homes Listed by qilin Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Holiday Skilled Nursing and Rehabilitation Center was listed by the qilin ransomware group on March 14, 2025, after internal files were exfiltrated in an attack. Individuals who may have received care or services from the facility should verify whether their information was exposed and follow any guidance issued by the organization.
Ransomware groups continue to target healthcare and long-term care providers, where operational disruption and sensitive personal data create strong leverage. In this environment, the listing of The Holiday:Adult Care Community & Retirement Homes by the qilin ransomware group, reported on March 14, 2025, fits a familiar pattern of claimed data theft followed by a public deadline for release.
Public detail remains limited. The group claims to have exfiltrated internal files and states that all data of the company will be available for download on 29.05.2025. The number of people affected is unknown, and independent confirmation of the intrusion or the full scope of material has not been provided in the available record.
Breaking down the breach
According to the reported listing, The Holiday:Adult Care Community & Retirement Homes was named by the qilin ransomware group on or around March 14, 2025. The claim states that internal files were exfiltrated in a ransomware attack and that the full set of company data would be made available for download on 29 May 2025. No public figure has been given for the volume of data, the number of systems involved, or the precise method of initial access. The count of individuals potentially affected is listed as unknown. Beyond the group’s own assertion on its leak site, further technical detail—such as whether encryption occurred, whether a ransom demand was issued, or whether the organisation has verified the claim—has not been disclosed in the facts available.
The organisation is described in related material as Holiday Skilled Nursing and Rehabilitation Center in Manville, a family-owned facility serving Northern Rhode Island since 1973. That description appears to originate from the facility’s own public-facing language rather than from forensic findings about the incident itself.
Who is qilin?
Qilin is a well-documented ransomware-as-a-service operation that has been active for several years. Public reporting consistently describes the group as using double-extortion tactics: encrypting systems where possible while also stealing data and threatening to publish it if payment is not made. Affiliates typically gain access through common initial vectors such as phishing, compromised remote-access credentials, or unpatched vulnerabilities, then move laterally to locate high-value files before deploying ransomware and opening negotiations.
The group maintains a leak site on which it posts victim names, sample files, and countdown timers for full data release. Listings on that site are claims by the operators; they are not independent confirmations of successful intrusion or of the completeness of any stolen archive. Qilin has previously targeted organisations across manufacturing, professional services, education, and healthcare-related sectors. Nothing in the present record goes beyond the group’s assertion that The Holiday:Adult Care Community & Retirement Homes is among its victims and that a download deadline of 29 May 2025 was set.
About The Holiday:Adult Care Community & Retirement Homes
The Holiday:Adult Care Community & Retirement Homes operates as a skilled nursing and rehabilitation centre in Manville, Rhode Island. Public descriptions characterise it as a family-owned facility that has served Northern Rhode Island since 1973. Organisations of this type provide residential care, medical support, rehabilitation services, and daily living assistance to older adults and others requiring long-term or post-acute care.
Such facilities routinely maintain extensive records: medical histories, medication lists, insurance and billing information, contact details for residents and next of kin, staff employment files, and operational documents. Because the population served is often medically vulnerable and dependent on continuous care, any disruption to systems or any exposure of personal health information carries heightened practical consequences. The listing therefore raises concerns both for the continuity of services and for the privacy of residents, families, and employees.
What was likely exposed
The available facts state only that “internal files” were exfiltrated in a ransomware attack. No inventory of specific data categories—such as medical records, financial documents, employee information, or resident contact lists—has been publicly confirmed. The group’s claim that “all data of this company” would be released on 29 May 2025 remains an unverified assertion.
In the ordinary course of business, adult care communities and skilled nursing facilities hold protected health information, Social Security numbers or other identifiers, insurance details, emergency contacts, and staff personnel records. Whether any or all of those categories were among the files taken in this incident is unconfirmed. Readers should treat the precise contents as unknown until the organisation or independent investigators provide further detail.
Why it matters
For residents and their families, exposure of health or identity data can increase the risk of medical identity theft, fraudulent insurance claims, or targeted social-engineering attempts that exploit knowledge of a person’s care situation. Staff whose employment or personal information may have been included face similar identity-theft and phishing risks. Because the number of people affected is unknown, the scale of any such risk cannot yet be quantified.
For the organisation itself, a claimed ransomware incident can disrupt clinical and administrative systems, strain limited resources, and require costly recovery and notification efforts. Even when encryption is not confirmed, the mere threat of public data release can damage trust among residents, families, and referring providers. The May 2025 deadline cited by the group adds a fixed point of pressure, though whether any release ultimately occurred is outside the facts provided here.
What to do if you're exposed
If you are a resident, family member, or employee associated with The Holiday:Adult Care Community & Retirement Homes, monitor financial and insurance statements for unexpected activity and consider placing a fraud alert or credit freeze with the major credit bureaus. Be cautious of unsolicited calls or messages that reference your care or personal details; verify any such contact through known official channels. Request written confirmation from the facility about whether your information was involved once any formal notification process begins. As a practical first check, you can run a free exposure scan of your email address to see whether it has already appeared in known breach data sets, then act on any confirmed findings with password changes and multi-factor authentication where available.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Georgia Dermatology & Skin Cancer Center Listed by qilin Ransomware GroupShore Gardens Rehabilitation & Nursing Center Listed by qilin Ransomware GroupThe Blood and Marrow Transplant Group of Georgia Listed by qilin Ransomware Group1sthealthinc.com Listed by qilin Ransomware GroupLatest breaches
Publicly posted by qilin — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.