Legend Senior Living 2025 Data Breach

Legend Senior Living Assisted Living Operator Breach (2025): 996K Resident & Staff Records Including SSN Exposed via Ransomware

Company · Senior housing and care services · Residential care network · USA

Legend Senior Living Assisted Living Operator Breach (2025): 996K Resident & Staff Records Including SSN Exposed via Ransomware

Senior housing and assisted living operator.

Confirmed · ObscureIQ Intelligence
Breach Risk Index i
69/100
Lower riskHigher risk
High and current: recent, valuable data circulating on the dark web now.
Data Sensitivity i
Elevated
Exposed data raises the risk of fraud, targeting, and impersonation. Proactive steps are warranted.
996K records (parse); official total undisclosedRecords
2025Year

The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.

Crucial data exposed
SSNSocial Security Number
AddressPhysical address
Classification Tags
World LeaksRansomware / ExtortionHealthcareSenior CareMembers2025

Breach Summary

Legend Senior Living, a Wichita-based senior-living operator, was accessed by an unauthorized actor between about July 27 and August 15, 2025; the WorldLeaks extortion group posted a leak claim on September 18, 2025. A DataBreach.com parse of the leaked data found roughly 409,300 emails, 996,000 home addresses, 576,000 phone numbers, and 32,700 Social Security numbers (distinct values that overlap across individuals). Legend's official notifications (April 10, 2026) reported exposure of names, addresses, SSNs, driver's licenses, government IDs/passports, financial account information, and medical/health-insurance data. State filings disclosed only small subsets (e.g., 5,006 Texas residents; 12 MA; 6 ME; 4 NH) and the national total remains undisclosed; the 996,013 figure is a raw address-parse count and likely overstates distinct affected individuals.

Full threat analysis, exploitation vectors, and principal guidance below.

11 additional sections · verified field analysis · defensive doctrine

Querying breach corpus…
Cross-referencing exposed field types…
Resolving threat-actor attribution…
Compiling principal risk advisory…

996K records (parse); official total undisclosed records analyzed

About Legend Senior Living

Legend Senior Living is a U.S. senior-housing and assisted-living operator headquartered in Wichita, Kansas, operating residential-care communities across Colorado, Florida, Kansas, Missouri, Oklahoma, Pennsylvania, and Texas. It maintains resident identity, health and care, billing, and family/guardian records along with employee data.

Why They Hold Your Data

Senior-living providers collect resident identity, contact, health and care records, billing information, family or guardian details, and operational records across residential-care workflows.

Recent Developments

An unauthorized actor accessed Legend servers between roughly July 27 and August 15, 2025; the WorldLeaks extortion group posted a claim on September 18, 2025. Legend preliminarily completed its file review on March 12, 2026 and began notifying affected individuals on April 10, 2026, offering credit monitoring through Cyberscout (a TransUnion company). Multiple class-action investigations followed.

Data Points Exposed

4 verified field types
Email Address
Phone Number
Physical address High
Social Security Number Critical

Breach Impact

Because the records tie individuals to an elder-care operator, exposure signals a vulnerable, dependency-prone population that fraudsters actively target. Confirmed circulating identifiers (names, addresses, phones, Social Security numbers) create identity-theft and elder-scam risk; Legend’s notification additionally reported driver’s licenses, passports/government IDs, financial account information, and medical/health-insurance data, which would sharply increase medical- and financial-fraud risk if in the full dump. The breach also affects residents’ families and staff.

Exploitation & Downstream Threats

• Elder-targeted scams, coercion, and financial exploitation using resident identity and contact data | • Identity theft and synthetic identity construction using SSN | • Doxxing and physical targeting from exposed home addresses | • SIM swap and vishing attacks where phone numbers are present | • Potential medical- and financial-fraud if reported ID/financial/health data is in the dump | • Family/guardian-directed social engineering

Principal Risk Advisory

What this means for a principal

A healthcare-linked breach: exposure ties a named individual to a provider relationship and, where clinical or insurance data is present, to conditions and treatment. For a high-profile principal this is targeting-grade, not merely identity-theft-grade: the combination lets an adversary locate, impersonate, or pressure the principal with little additional work.

What You Should Do

  1. Freeze credit at all three bureaus and monitor for new-account and tax-refund fraud.
  2. Treat the home address as exposed: review mail and package handling and physical-security routines, and brief household staff to verify unusual requests.
  3. Guard against SIM-swap and vishing: add a carrier port-out PIN and verify any 'support' calls independently.
  4. Do not use unofficial 'am I affected' lookups; several are themselves harvesting operations.

How ObscureIQ Can Help

  1. Corpus confirmation: determine whether and where the principal (plus household and staff) appear in this dataset and which specific fields are exposed for them.
  2. Exposure mapping and footprint neutralization: cross-reference against broker-available data and suppress still-removable elements, prioritizing address and phone, since this record re-seeds broker networks.
  3. ThreatWatch tuned to this incident's identifiers and misuse pattern (impersonation and targeting patterns, not generic credential monitoring).
WL
Threat Actor: World LeaksConfidence: High
Extortion-as-a-service / rebrand

Motivation: Financial extortion
A leak extortion operation described as a rebrand or successor evolution of Hunters International. Reporting describes a shift toward extortion-only operations rather than encryption-first ransomware, with affiliate infrastructure and data leak pressure.

Read the full threat-actor profile →

Protect Yourself

Check If You're Affected

Enter your email to check whether your data appears in this breach. We’ll send a 6-digit code to confirm it’s your address.

High-Risk? Get an Exposure Audit

Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.

Request Consultation