On November 19, 2024, the American Academy of Family Physicians was listed on the leak site operated by the hunters ransomware group. The entry states that AFD suffered a ransomware attack in which internal files were exfiltrated. The disclosure indicates data was taken but does not specify the volume or exact categories of information involved, nor does it list any ransom demand or negotiation status.
Watch AFD
Get alerted the next time AFD files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about AFD’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Details from the Leak-Site Listing
The hunters leak page for AFD states that the organization is based in the United States, that data was successfully exfiltrated, and that the victim’s systems were not encrypted. No sample files are currently posted, and the listing does not quantify how many records or which specific document types were taken. As is typical with these extortion sites, the group is using the threat of public release to pressure the victim. The exact date of initial compromise remains unknown from the public listing.
Why This Matters for You and Your Family
When a professional association like the American Academy of Family Physicians is breached, the people affected are often everyday physicians, clinic staff, and their patients. Internal files can easily contain names, addresses, dates of birth, Social Security numbers, medical billing records, or employment details. If any of that information belongs to you or someone in your household, it can be used for identity theft, tax fraud, or targeted phishing. Even if you are not a direct member, vendor records, donor lists, or partner contracts frequently include personal data of ordinary families.
The Doxxing and Identity-Chain Risk
Exfiltrated internal files frequently contain email addresses, usernames, and passwords that link professional identities to personal ones. A single leaked credential from an AFD system can be reused against your personal email, online banking, or social-media accounts. These connections form doxxing chains: an attacker who obtains your work email can quickly map it to your home address, phone number, and family members’ profiles. Gaming accounts belonging to children are especially vulnerable because the same password habits often cross from parent to child, turning one breach into household-wide exposure.