Alegria Family Services
| Primary URL | Location | Industry | www[.]alegriafamilyservices[.]org |
Country
United States of America
|
Healthcare
|
|---|
Profile
Alegria Family Services, also known as AFS, is a provider of residential and community services for adults with developmental disabilities. The organization is based in New Mexico and its headquarters is located in the United States of America. It focuses on delivering support that helps individuals live in community settings and receive residential care as needed. Its services are tailored to the specific needs of adults who have developmental disabilities.
The organization maintains records that span up to six years of client and personnel information. In the incident reported in September 2022, it needed to notify approximately one hundred individuals initially, with plans to reach additional clients whose records covered the full six‑year period. This indicates that Alegria Family Services serves a client base that accumulates over multiple years of service provision. The need to contact both current and past clients reflects the longitudinal nature of its record keeping.
In September 2022, Alegria Family Services experienced a ransomware attack carried out by the BianLian group. The attackers bypassed existing antivirus protections by fragmenting files before encryption. They encrypted the organization’s active files and also compromised its cloud‑based backups. As a result, a six‑year archive of data became inaccessible, leaving only a three‑day‑old Windows backup usable. Alegria Family Services was unable to meet the ransom demand imposed by the attackers. Consequently, the organization prioritized notifying all affected individuals about the breach. Notification was conducted primarily through personal phone calls, a method chosen because many clients have cognitive needs that require direct communication. Where telephone contact information was not available, the organization used letters or substitute notices to reach those individuals. At the time of public reporting, the BianLian group had not leaked the exfiltrated data. The incident highlighted the organization’s reliance on backups and the challenges of securing data for a population with specific communication requirements.
