Skip to content
Back to Blog
high severity September 01, 2026 · 3 min read Unverified claim — what this is

uicc.org Listed by Krybit Ransomware Group

If you are a customer of uicc.org, here’s what is being claimed, and what it would mean for you.

The Union for International Cancer Control (UICC) is the world's largest international cancer membership non-profit orga...

— from Krybit’s own leak-site posting. This is the group’s claim, quoted verbatim; it is not GalaxyWarden’s reporting and has not been independently verified.
uicc.org Listed by Krybit Ransomware Group

The Union for International Cancer Control has been listed on the Krybit ransomware-extortion leak site. According to the listing, dated September 01, 2026, the group claims to have obtained files from uicc.org. The organisation has not publicly confirmed the claim as of this writing.

Watch uicc.org

Get alerted the next time uicc.org files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.

We’ll email you only about uicc.org’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.

Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.

If the claim is accurate, the people whose records appear in the filing now face the uncertainty that comes with any unverified extortion listing. No categories of information are named in the record, and the filing does not state how many individuals may be involved. This means you cannot tell from the public listing whether any record that might belong to you was included, what it contained, or whether the claim itself is genuine.

Your Password May Still Be Protected

The listing mentions credential exposure but does not disclose how passwords were stored. Because the hashing or encryption method is unknown, treat your UICC account password as potentially compromised. Change it immediately on uicc.org and, more importantly, change it everywhere else you have reused the same password. Reused passwords turn a single uncertain claim into a risk across every account that shares it.

Exposure Pack · one payment
The full list, and what to lock in ten minutes.
  • Every indexed leak tied to your address — all of them, named and dated
  • What this kind of incident typically exposes
  • A ten-minute lock list written for this kind of organisation
One payment. Nothing renews, and no account is created. Emailed to you within a minute.

No permanent government or biographic identifiers are listed in the record. That is one piece of genuinely good news: nothing here permanently ties new fraud to your name in the way a stolen Social Security number or passport number would.

What a Leak-Site Listing Actually Establishes

Ransomware and extortion groups frequently publish targets on leak sites to pressure payment. These listings are marketing material produced by the claimant. They are not audited inventories. Many turn out to be recycled data from older incidents, exaggerated claims, or sometimes entirely false. The absence of confirmation from the named organisation, a regulator, or an independent breach-notification filing means the claim remains exactly that — a claim.

Real confirmation would require the organisation itself to state that an incident occurred, what was taken, and who was affected. Until that happens, the safest posture is cautious skepticism rather than assuming the worst or assuming safety. The record supplies no discovery date and no incident date separate from the September 01, 2026 filing date, so there is no reliable timeline to judge response speed or containment.

The Pattern Seen in Health and Non-Profit Targets

Extortion crews have repeatedly listed international non-profits and health-related organisations, knowing that public pressure and donor sensitivity can encourage faster negotiation. Some of these listings later prove accurate; others are later walked back or simply disappear without explanation. The pattern gives context but does not resolve the uncertainty for this specific listing. It does, however, suggest that similar claims against organisations in the same sector are likely to appear again. Watching for direct notification remains the only reliable way to know whether your own records were involved.

What You Can Still Control

Because the record lists no specific data categories, the practical steps focus on reducing the impact of any potential credential compromise and staying alert for future contact.

  • Change your UICC password immediately and do not reuse it anywhere else. This limits damage if the claimed credential exposure is real.
  • Enable two-factor authentication on your UICC account and every other account that offers it. Strong second factors block most credential-stuffing attacks even if a password has been obtained.
  • Monitor your accounts and credit reports for unexpected activity. Although no permanent identifiers are listed, unusual login attempts or changes to contact details can still signal attempted fraud.
  • If you receive a letter or email from UICC about this matter, read it carefully. The organisation is required to notify affected individuals directly if the claim is substantiated and individuals are in scope. Absence of a letter usually indicates you were not included, but anyone who has changed address since 2026 should contact UICC to confirm their status.

Staying informed without assuming the worst protects both your time and your peace of mind. GalaxyWarden provides continuous monitoring across 13.1B+ breach records and 100+ platforms, with identity-chain mapping and remediation support by specialists.

What the free scan actually returns

Sample resultyou@email.comIllustrative — not a real person

Found on people-search siteswe remove these

These listings are live, public, and legal to remove — and removing them is what we do.

value redacted in this sampleage, relatives, address historySpokeo
value redacted in this samplephone, household, property recordsBeenVerified
value redacted in this sample580 companies checked

Found in breach recordsverifiedreported — unverified

Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.

verifiedvalue redacted in this samplepassword + phone · 2024telecom breach
unverifiedvalue redacted in this sampleclaimed in ransomware listing · 2026leak-site claim

Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.

Check your exposure
uicc.org is one listing. Your email is probably in others.
We can’t confirm any single incident against the sources we search, so we won’t pretend to. What we can show you is your own exposure — your email against 13.1B+ leaked records and the sites that publish your address. About 15 seconds. No account, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Report details & sourcing

Severity High the filing does not enumerate what was exposed
Disclosed September 01, 2026
Last reviewed September 1, 2026
Affected Unconfirmed
Unverified claim — what this report is
This page documents a public listing on a ransomware/extortion group’s leak site, tracked via public threat-intelligence sources. A listing is the attacker’s claim. GalaxyWarden aggregates and reports such claims; we have not independently verified that a breach occurred, what data (if any) was taken, or the accuracy of anything the group asserts, and the named organisation has not necessarily confirmed the incident. Sections above describe what the listing shows and the group’s documented history — not verified findings about the named organisation. If you represent this organisation and believe anything here is inaccurate, tell us and we’ll review it promptly.
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email