Data breach
Rockwood Retirement Communities
- Records
- 132,606
- Breach date
- 26 February 2026Estimated
- Added
- 27 July 2026
What was exposed
9 types of data · 5 more reported · 2 put you at serious risk
- Names132,606
- Phone numbers68,945
- Email addresses45,690
- Street addresses33,757
- Dates of birth29,862
- Social security numbers9,465
- Licence plates766
- Driving licence numbers40
- Vehicle VINs33
- Government IDsReported, not counted
- Passport numbersReported, not counted
- Bank account numbersReported, not counted
- Medical recordsReported, not counted
- Insurance detailsReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
Rockwood Retirement Communities, a nonprofit senior living organization in Spokane, Washington, suffered a data breach that exposed sensitive personal information belonging to residents and other individuals. The incident traces back to late February 2026, when a data extortion group known as Kairos listed the organization on its leak site. According to our investigation team, the indexed dataset associated with this listing contains approximately 132,606 records, including names, phone numbers, email addresses, street addresses, dates of birth, and Social Security numbers.
The organization itself, which operates as Spokane United Methodist Homes doing business as Rockwood, disclosed the incident in an August 2026 notice. According to ClassAction.org, the company became aware of suspicious network activity on or around February 16, 2026, and later determined that certain files may have been acquired without authorization. The method of attack has not been publicly described.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
February 16, 2026: Rockwood detected suspicious activity on its network, according to the company's August 2026 notice.
February 27, 2026: Ransomware.live recorded the Kairos group listing Rockwood Retirement Communities on its leak site, with an estimated attack date of February 26, 2026.
July 27, 2026: The company completed its review of affected files and determined what information was involved, per ClassAction.org.
August 20, 2026: Rockwood posted its breach notice and began mailing notification letters to affected individuals.
August 25, 2026: The breach was reported to the Massachusetts Office of Consumer Affairs and Business Regulation as filing No. 2026-1424.
What Information Was Compromised?
Our analysis found the following data types in this breach: names for 132,606 individuals, 68,945 phone numbers, 45,690 email addresses, 33,757 street addresses, 29,862 birthdays, 9,465 Social Security numbers, 766 vehicle plates, 40 driver's licenses, and 33 vehicle VINs.
The company's own notice lists additional fields not captured in our indexed dataset. According to ClassAction.org, Rockwood's review found the exposed information varied by individual and could include Social Security numbers, dates of birth, driver's license or state identification numbers, passport numbers, financial account information, Medicaid or Medicare numbers, medical information, and health insurance information.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
Social Security numbers combined with dates of birth and financial account information carry a long-term identity theft risk. Criminals can use this combination to open new credit accounts, file fraudulent tax returns, or commit medical identity fraud. For seniors, Medicare-related identity theft is a particular concern, since medical services billed under a stolen number can be difficult to detect and unwind. Exposed email addresses and phone numbers also raise the risk of targeted phishing attempts that impersonate healthcare providers or financial institutions.
What Is Rockwood Retirement Communities Doing in Response?
Rockwood began mailing notification letters on August 20, 2026, and is offering affected individuals 24 months of complimentary credit monitoring and identity protection services through Cyberscout, a TransUnion company. Enrollment requires a unique activation code from the notification letter and must be completed by November 20, 2026. The organization has also set up a dedicated incident-response line at 1-866-898-5714, staffed by TransUnion representatives Monday through Friday from 5 a.m. to 5 p.m. Pacific Time, excluding major holidays. The notice does not state how the systems were compromised, and that detail remains unclear.
What Should You Do If You Were Affected?
Enroll in the free 24-month credit monitoring at bfs.cyberscout.com/activate using the code in your letter before the November 20, 2026 deadline.
Place a fraud alert or security freeze with Equifax, Experian, and TransUnion.
Check your credit reports for free at annualcreditreport.com or by calling 1-877-322-8228.
Review bank, credit card, and Medicare or insurance statements closely for unfamiliar activity.
Report suspected identity theft to the Federal Trade Commission at IdentityTheft.gov or 1-877-ID-THEFT.
In the news
- ClassAction.org investigation pageclassaction.org (opens in a new tab)
- Massachusetts AG breach filing No. 2026-1424 (PDF)mass.gov (opens in a new tab)
- Ransomware.live victim listing for Rockwood Retirement Communitiesransomware.live (opens in a new tab)
- ClaimDepot breach reportclaimdepot.com (opens in a new tab)
