On September 30, 2023, the Order of Psychologists of Lombardy appeared on the leak site of the noescape ransomware group. The listing states that the organization’s network was successfully encrypted and compromised during a ransomware attack, and that internal files were exfiltrated. The group warns that if management continues to remain silent, the stolen data will be published.
Watch Order of Psychologists of Lombardy
Get alerted the next time Order of Psychologists of Lombardy files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Order of Psychologists of Lombardy’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Details from the Leak-Site Listing
The primary disclosure on the noescape onion site states the victim as the Order of Psychologists of Lombardy, an Italian professional regulatory body. It explicitly states that internal files were exfiltrated and that the network was encrypted. The listing does not quantify the number of affected records, name specific file types, or detail the volume of data taken. It also does not provide a ransom demand or a publication deadline beyond the general threat that continued silence will result in release of the material. Public reporting on noescape indicates this style of posting — encryption plus public shaming — is standard for the group when initial extortion attempts fail.
Why This Matters for You and Your Family
Even though the victim is a professional licensing body, the people whose information appears in its internal files are ordinary psychologists, their patients, administrative staff, and potentially their families. If your therapist, counselor, or a family member’s mental-health provider is licensed in Lombardy, your name, contact details, or clinical notes may now sit in a ransomware actor’s archive. Internal files exfiltrated in ransomware attacks frequently contain contracts, licensing records, payment information, correspondence, and personal identifiers that can be used for identity theft, targeted phishing, or blackmail. The disclosure indicates the data remains at risk of public release, meaning anyone connected to the Order could face sudden exposure.
The Doxxing and Identity-Chain Implications
Ransomware groups like noescape rarely stop at the initial victim. Once internal files are in their possession, actors scan for email addresses, phone numbers, and usernames that can be cross-referenced against other breaches. These linkages create long identity chains that connect professional licensing data to personal accounts, social-media handles, and even children’s gaming profiles. A single leaked work email from a psychologist’s record can unlock personal banking portals, family cloud storage, or school communications if passwords were reused. Credential leaks like this one cascade into account takeovers and doxxing chains that can affect every member of a household. Children’s gaming accounts are especially vulnerable because parents often reuse credentials across work, personal, and family gaming services.