On July 29, 2023, the Village Church of Barrington appeared on the leak site operated by the nokoyawa ransomware group. The listing states that internal files were exfiltrated during a ransomware attack on the Texas-based religious institution founded in 1977. The disclosure does not quantify how many individuals are affected, nor does it list specific categories of personal data.
Watch Village Church of Barrington
Get alerted the next time Village Church of Barrington files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Village Church of Barrington’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Details in the Leak-Site Listing
The primary disclosure on the nokoyawa leak site indicates that the church’s internal files were taken and are now published for anyone to download. It does not detail the volume or exact contents of the material. The entry carries the standard extortion language used by this group, threatening further publication if demands are not met. Public copies of the leak site, archived through ransomware.live, state the July 29, 2023 posting date and the church’s name and location in Mound, Texas.
Why This Matters for You and Your Family
When a church is breached, the people whose information appears in its files are ordinary congregants, volunteers, donors, staff members, and their families. Names, addresses, phone numbers, email addresses, dates of birth, and financial details tied to tithes or donations can easily surface. Even if the leak-site listing does not specify every data type, internal church records routinely contain exactly this kind of information. Once released on a dark-web leak site, copies spread quickly to other criminal forums, increasing the chance that identity thieves or harassers will obtain it.
Doxxing and Identity-Chain Risks
Church membership rolls frequently link an individual’s real name and home address to an email address, cell-phone number, and sometimes spouse or children’s names. Those same email addresses and phone numbers are often reused for personal accounts, online shopping, and children’s gaming logins. A single leak therefore becomes the starting point for an identity chain: attackers correlate the church data with other breaches, map additional accounts, and escalate to full doxxing or account takeover. Credential leaks of this nature regularly cascade into gaming-platform compromises, where children’s accounts become entry points for further harassment or extortion aimed at the household.