[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fuMUOvm3kcmCbkgoX71egbsPQCyece5v1lIhEOVAs7Rs":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"company":11,"breachDate":15,"addedDate":16,"modifiedDate":16,"pwnCount":17,"totalRecords":17,"dataClasses":18,"description":27,"source":28,"isVerified":4,"isSpamList":29,"isSensitive":4,"severity":30,"processingStatus":31,"logoUrl":32,"contentUpdatedAt":16,"hasEnglishDescription":4},"6a66e5e1d35215fc8c235eb1","SpindletopCenter2025","Spindletop Center 2025 Data Breach","spindletop-center-2025","spindletopcenter.org",{"name":12,"sector":13,"country":14,"website":10},"Spindletop Center","Healthcare","United States","2025-09-23T00:00:00.000Z","2026-07-27T05:00:17.907Z",88863,[19,20,21,22,23,24,25,26],"Personal information","Protected health information","Names","Social Security numbers","Driver's license numbers","Government identification numbers","Diagnosis information","Case numbers","\u003Cp>\u003Cstrong>The Spindletop Center 2025 data breach\u003C\u002Fstrong> was a cyberattack affecting the Texas behavioral-health organization's systems and identified on September 29, 2025. The notice issued on the organization's behalf confirms that an unauthorized party may have accessed sensitive information on September 23 and that the event made systems and servers inoperable for a limited time.\u003C\u002Fp>\n\u003Cp>The public record maintained by the U.S. Department of Health and Human Services Office for Civil Rights lists Spindletop Center as a Healthcare Provider and classifies the event as a Hacking\u002FIT Incident involving a Network Server; 88,863 people were affected. LeakData imported no client rows, importedRecordCount is zero, and this entry contains verified incident metadata only.\u003C\u002Fp>\n\u003Ch2>How Was the Spindletop Center Breach Confirmed?\u003C\u002Fh2>\n\u003Cp>The primary source is the notice to individuals issued on behalf of Spindletop Center. It directly describes discovery of the cyberattack, the access date, completion dates for the investigation and data review, potentially exposed fields, the status of known misuse, and measures taken by the organization.\u003C\u002Fp>\n\u003Cp>The second source is the HHS OCR breach portal, which confirms the federal total of 88,863 people and the incident classifications. SC Media independently reports that the Rhysida group claimed the Spindletop Center attack. Because the organization's own notice names neither an actor nor ransomware, the attribution is treated as a public threat-actor claim rather than a conclusive technical finding.\u003C\u002Fp>\n\u003Ch2>What Happened Between September 23 and 29, 2025?\u003C\u002Fh2>\n\u003Cp>The investigation found that an unauthorized party may have accessed sensitive information on Spindletop systems on September 23. The organization identified the cyberattack on or about September 29, after some systems and servers became unavailable for a limited period. Spindletop engaged outside cybersecurity experts to assess, contain, and remediate the incident and notified law enforcement.\u003C\u002Fp>\n\u003Cp>The technical investigation concluded on December 3, 2025. Spindletop then performed a detailed review to identify the people associated with potentially affected information and locate valid addresses; that process ended on December 30. The breachDate field uses September 23, the possible access date confirmed by the organization, rather than the discovery or review date.\u003C\u002Fp>\n\u003Ch2>What Information Was Affected?\u003C\u002Fh2>\n\u003Cp>The notice lists first and last names, Social Security numbers, driver's-license or other government-identification numbers, diagnosis information, and case numbers as potentially exposed. The combination of identity numbers with diagnosis data in a behavioral-health context makes this a highly sensitive breach of personal and protected health information.\u003C\u002Fp>\n\u003Cp>Spindletop specifically said the data types varied by person and that not every individual had all listed fields exposed. This entry therefore creates no subgroup counts and does not add undisclosed addresses, dates of birth, email addresses, passwords, payment cards, bank accounts, or health-insurance identifiers. The organization also did not confirm public release of the data.\u003C\u002Fp>\n\u003Ch2>What Does the 88,863-Person Scope Mean?\u003C\u002Fh2>\n\u003Cp>The pwnCount and totalRecords fields use the 88,863 affected-person count in the current HHS OCR public row. It is not a count of files, therapy sessions, case documents, diagnoses, or individual data elements. Because one person may have multiple fields involved, the data categories have not been added together to construct a different scope.\u003C\u002Fp>\n\u003Cp>Spindletop Center is a nonprofit community organization providing behavioral healthcare, programs for people with intellectual and developmental disabilities, substance-use recovery services, and crisis support. The sources do not disclose the distribution among current or former clients, employees, or other people, so this entry does not present those groups as separate totals.\u003C\u002Fp>\n\u003Ch2>What Measures Did Spindletop Take?\u003C\u002Fh2>\n\u003Cp>After identifying the attack, the organization said it worked with outside cybersecurity experts on assessment, containment, and remediation and notified law enforcement. Spindletop also implemented additional safeguards, improved physical security related to cybersecurity, and said it continues to strengthen its policies, procedures, and protocols.\u003C\u002Fp>\n\u003Cp>As of the notice, Spindletop had found no evidence that information in its care had been specifically misused. Even so, Social Security and government-identification numbers create a lasting identity-theft risk. The absence of known misuse does not guarantee that fraud will not occur later and does not make protective monitoring unnecessary.\u003C\u002Fp>\n\u003Ch2>What Should Affected People Do?\u003C\u002Fh2>\n\u003Cp>Notice recipients should regularly review credit reports and new-account inquiries and consider placing a free fraud alert or credit freeze where appropriate. An unfamiliar account or use of an identity should be reported through official channels to the relevant institution, law-enforcement agency, and appropriate attorney general's office.\u003C\u002Fp>\n\u003Cp>Messages containing diagnosis or case details can make targeted healthcare phishing convincing. Links in unexpected communications claiming to be from Spindletop, a treatment center, public agency, or credit bureau should not be opened directly; contact should begin through the organization's official site or a previously verified number. LeakData does not host, distribute, or provide search access to stolen personal or health information.\u003C\u002Fp>","Spindletop Center notice confirming a cyberattack and potential exposure of sensitive information",false,"Medium","completed","\u002Fuploads\u002Flogo\u002Fspindletopcenter_org.png"]