Graceworks Lutheran Services
bd_1849ecc5f654a133 · schema v1 · pii pii-v1
Full breach record for Graceworks Lutheran Services →2 incidents on fileThreat-actor claim — not a regulatory filing
This row is a claim by the ransomware group BlackSuit (formerly Royal) on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Source: Ransomware.live
Post text · scraped from the leak site
Founded in 1929, Graceworks Lutheran Services is a lutheran social services organization that operates assisted living facilities. Do not be surprised that the company is engaged in charity - it's just a front. Maybe they are involved in money laundering - who knows...We have at our disposal the contents of all email addresses of the top management, full financial audits from 1995 to the present, 45GB or 486,880 Files of personal patients information (clinical) and even documents related to President Biden - very entertaining. Beside this, we have finance, employee documents, accounting, HR and much more others.Enjoy!
J jump to incidentP pin to compareR raw source
Incident timeline — mostly unverified
? — ?
Breach window unknown
Mar 21, 2023
Claim posted
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Claim → filing
—
Compliance clock
Not assessable
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- HHS OCRbd_26108541f2e5e9a72023-04-19 · +29dCandidate
Filing propagation · 2 filings
View merged incident ↗Pattern: first filing Mar 21, last Apr 19 (OH) — a 29-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
Source ceiling
- actor name
- victim claim
- ransom/leak status
- discovery date
- materiality
- notification
- affected count
- confirmed data types
- compliance clock
The ✕ fields stay blank until a regulatory filing or victim disclosure lands.
blacksuit
According to ransomware.live, According to Trend Micro, this ransomware has significant code overlap with Royal Ransomware.