Operation PAR, Inc. 2025 Data Breach

Operation PAR Nonprofit Addiction Recovery Provider Breach (2025): 88K Records Including SSN & Contact Data Exposed via WorldLeaks Ransomware

Nonprofit · Addiction recovery and prevention services · Community health organization · USA

Operation PAR Nonprofit Addiction Recovery Provider Breach (2025): 88K Records Including SSN & Contact Data Exposed via WorldLeaks Ransomware

Nonprofit behavioral health and substance use treatment provider.

Confirmed · ObscureIQ Intelligence
Limited DisclosureThis breach is handled differently. Because being connected to it can itself be sensitive, we do not confirm anyone’s presence publicly.
Breach Risk Index i
77/100
Lower riskHigher risk
High and current: recent, valuable data circulating on the dark web now.
Data Sensitivity i
Restricted
Being associated with this breach can itself be harmful. Disclosure is limited and presence is not confirmed to unverified parties.
88KRecords
2025Year

The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.

Crucial data exposed
SSNSocial Security Number
AddressPhysical address
Classification Tags
World LeaksRansomware / ExtortionHealthcareAddiction2025

Breach Summary

Operation PAR, Inc., a Florida nonprofit addiction-treatment provider, detected unauthorized network access on or about June 10, 2025, with data potentially accessed between June 6 and June 10, 2025. The WorldLeaks ransomware/extortion group claimed responsibility, boasting of nearly 900,000 stolen files. DataBreach.com’s parse of the leaked set confirmed circulating fields of roughly 88,000 addresses, 13,200 phone numbers, 10,400 Social Security numbers, and 9,000 emails, and forensics indicated the cloud-based EHR was not compromised. The company’s notification additionally reported that names, medical records, and driver’s license information were involved; medical records and driver’s licenses were not confirmed in the parsed circulating dump. The incident was disclosed alongside related entities Boley Centers and digital-health vendor Eleos. Operation PAR posted a security-incident notice and began notifying affected individuals. Substance-use treatment records carry heightened protection under 42 CFR Part 2.

Full threat analysis, exploitation vectors, and principal guidance below.

11 additional sections · verified field analysis · defensive doctrine

Querying breach corpus…
Cross-referencing exposed field types…
Resolving threat-actor attribution…
Compiling principal risk advisory…

88K records analyzed

About Operation PAR, Inc.

Operation PAR, Inc. is a long-established Florida nonprofit providing substance-use disorder treatment, mental-health services, prevention programs, and related community behavioral-health support, primarily in the Tampa Bay/Pinellas County region. It maintains client identity, intake, insurance, counseling, and treatment records to coordinate care and recovery services.

Why They Hold Your Data

Addiction recovery and prevention nonprofits collect highly sensitive client identity, contact, treatment, counseling, insurance, and support-service records across recovery and community-health operations.

Recent Developments

Operation PAR posted a data-security incident notice and set up a dedicated help line after the June 2025 breach, which was disclosed alongside related entities Boley Centers and the digital-health vendor Eleos. Multiple class-action firms have opened investigations into the incident.

Data Points Exposed

5 verified field types
Email Address
Full Name
Phone Number
Physical address High
Social Security Number Critical

Breach Impact

Even limited to the confirmed circulating fields (names, addresses, phone numbers, emails, and Social Security numbers), the exposure signals association with substance-use disorder treatment, carrying severe stigma and discrimination risk on top of identity-theft and healthcare-fraud harm. If the notification-reported medical records and driver’s licenses are in the full dump, extortion and medical-fraud risk rises further. The breach undermined client trust in a highly sensitive care setting and implicates federally protected treatment data.

Exploitation & Downstream Threats

• Extortion and stigma-based targeting exploiting addiction-treatment status | • Medical identity fraud and insurance abuse using medical records | • Identity theft and synthetic identity construction using SSN and driver’s license | • Targeted phishing, smishing, and vishing using exposed contact data | • Doxxing and physical targeting from exposed home addresses | • Discrimination risk from disclosure of substance-use treatment

Principal Risk Advisory

What this means for a principal

A healthcare-linked breach: exposure ties a named individual to a provider relationship and, where clinical or insurance data is present, to conditions and treatment. For a high-profile principal this is targeting-grade, not merely identity-theft-grade: the combination lets an adversary locate, impersonate, or pressure the principal with little additional work.

What You Should Do

  1. Freeze credit at all three bureaus and monitor for new-account and tax-refund fraud.
  2. Treat the home address as exposed: review mail and package handling and physical-security routines, and brief household staff to verify unusual requests.
  3. Guard against SIM-swap and vishing: add a carrier port-out PIN and verify any 'support' calls independently.
  4. Do not use unofficial 'am I affected' lookups; several are themselves harvesting operations.

How ObscureIQ Can Help

  1. Corpus confirmation: determine whether and where the principal (plus household and staff) appear in this dataset and which specific fields are exposed for them.
  2. Exposure mapping and footprint neutralization: cross-reference against broker-available data and suppress still-removable elements, prioritizing address and phone, since this record re-seeds broker networks.
  3. ThreatWatch tuned to this incident's identifiers and misuse pattern (impersonation and targeting patterns, not generic credential monitoring).
WL
Threat Actor: World LeaksConfidence: High
Extortion-as-a-service / rebrand

Motivation: Financial extortion
A leak extortion operation described as a rebrand or successor evolution of Hunters International. Reporting describes a shift toward extortion-only operations rather than encryption-first ransomware, with affiliate infrastructure and data leak pressure.

Read the full threat-actor profile →

Protect Yourself

High-Risk? Get an Exposure Audit

Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.

Request Consultation