[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fRpnRI6TsEnnja1ZasL6wcNrNw46ITVpahu7g6UGZPLk":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"company":11,"breachDate":15,"addedDate":16,"modifiedDate":16,"pwnCount":17,"totalRecords":17,"dataClasses":18,"description":36,"source":37,"isVerified":4,"isSpamList":38,"isSensitive":4,"severity":39,"processingStatus":40,"logoUrl":41,"contentUpdatedAt":16,"hasEnglishDescription":4},"6a67184b4d5983ca61db70d2","WestminsterVillageGreenwood2025","Westminster Village Greenwood 2025 Data Breach","westminster-village-greenwood-2025","greenwoodvillagesouth.com",{"name":12,"sector":13,"country":14,"website":10},"Westminster Village Greenwood","Healthcare","United States","2025-02-11T00:00:00.000Z","2026-07-27T08:35:23.386Z",14386,[19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35],"Personal information","Protected health information","Full names","Addresses","Dates of birth","Social Security numbers","Driver's license numbers","Passport numbers","Financial account information","Usernames","Passwords","Medical record numbers","Medical diagnoses","Medical treatment information","Medications","Laboratory results","Health insurance information","\u003Cp>\u003Cstrong>The Westminster Village Greenwood 2025 data breach\u003C\u002Fstrong> resulted from unauthorized access to the network of a nonprofit senior-living and care organization in Indiana. The organization learned of the issue around February 12, 2025. A forensic review found that certain files may have been accessed or acquired by an unauthorized actor from approximately February 11 through February 17.\u003C\u002Fp>\n\u003Cp>Files could contain names, addresses, dates of birth, Social Security numbers, driver's-license numbers, passport numbers, financial-account data, usernames and passwords, plus medical-record numbers, diagnoses, treatment information, medications, lab results, and health-insurance information. An updated source-linked regulatory record reports 14,386 people. LeakData uses that figure for pwnCount and totalRecords; importedRecordCount is zero.\u003C\u002Fp>\n\u003Ch2>How Was the Westminster Village Greenwood Breach Confirmed?\u003C\u002Fh2>\n\u003Cp>The primary evidence is Westminster Village Greenwood's letter published in a Massachusetts consumer-notification file. On the organization's behalf, it directly describes network access, work with outside cybersecurity specialists, the period in which files may have been accessed or acquired, the January 23, 2026 data-review result, the misuse assessment, and the Experian service.\u003C\u002Fp>\n\u003Cp>A New Hampshire Attorney General file provides a separate official state notification trail. Claim Depot connects those filings and the organization's public notice and publishes the affected data classes, updated total of 14,386 people, and state subsets in structured form. The sources align on the organization, event window, possible access to or acquisition of files, and identity and health-data scope.\u003C\u002Fp>\n\u003Ch2>What Happened From February 11 Through February 17, 2025?\u003C\u002Fh2>\n\u003Cp>Westminster Village Greenwood experienced unauthorized access to its network around February 12 and opened an investigation with outside cybersecurity professionals. The forensic team found that data potentially may have been accessed or acquired by an unauthorized actor. The organization then engaged a vendor for a comprehensive manual review to identify the contents of the potentially affected files and the people to whom they related.\u003C\u002Fp>\n\u003Cp>The lengthy forensic and manual review was completed on January 23, 2026 and found that certain files may have been subject to unauthorized access or acquisition from approximately February 11 through February 17, 2025. Public sources do not identify the initial access method, actor, malware, ransom demand, or publication of data. The qualified language does not establish that every file was definitely copied.\u003C\u002Fp>\n\u003Ch2>What Identity and Account Information Was Affected?\u003C\u002Fh2>\n\u003Cp>The scope varies by individual but may include full names, addresses, dates of birth, Social Security numbers, driver's-license numbers, and passport numbers. Together, these persistent identifiers can enable fraudulent credit, tax-identity misuse, document fraud, and targeted social engineering. It should not be assumed that every affected person had all of these fields present.\u003C\u002Fp>\n\u003Cp>Sources also report that usernames and passwords may have been affected. Notice recipients should replace reused or similar passwords with unique credentials, enable multifactor authentication when available, and review active sessions. If an SSN was involved, free freezes at all three major credit bureaus, a fraud alert, and an IRS Identity Protection PIN may be appropriate.\u003C\u002Fp>\n\u003Ch2>What Is the Risk From Financial-Account Information?\u003C\u002Fh2>\n\u003Cp>Affected files could contain financial-account information. This broad category can support account-related fraud, fraudulent payment redirection, or phishing that targets a person with accurate institutional context. Public documents do not, however, separately confirm a bank name, account type, routing number, payment card, CVV, PIN, balance, or transaction history.\u003C\u002Fp>\n\u003Cp>LeakData does not add financial details unsupported by the source. Recipients should monitor bank and credit activity for unfamiliar transactions, new payees, or contact-information changes. One-time codes and passwords should not be given during unexpected calls claiming to come from Westminster Village, Experian, or a bank; call back through an independently obtained official channel.\u003C\u002Fp>\n\u003Ch2>What Medical and Insurance Data Was in Scope?\u003C\u002Fh2>\n\u003Cp>Protected health information included medical-record numbers, medical diagnoses, treatment information, medications, lab results, and health-insurance information. That combination can expose a person's particular care relationship and clinical details. It creates risk of medical-identity misuse, fraudulent service claims, or scams that target residents and families using authentic treatment context.\u003C\u002Fp>\n\u003Cp>Recipients should review explanation-of-benefits statements, patient portals, and provider accounts for services, prescriptions, lab results, or contact changes they do not recognize. Suspicious entries should first be verified with the provider and insurer. Because public sources do not say that each person had the same clinical fields, data classes represent the incident-wide possible scope while individual letters define person-specific exposure.\u003C\u002Fp>\n\u003Ch2>How Many People Were Affected and How Did the Organization Respond?\u003C\u002Fh2>\n\u003Cp>The updated source-linked record reports 14,386 affected people nationwide. Six Massachusetts residents and three New Hampshire residents are subsets of that national figure and are not added again. The organization letter says it had no evidence at notification time that information had been misused for identity theft or financial fraud. That time-bound assessment does not eliminate future risk.\u003C\u002Fp>\n\u003Cp>Westminster Village investigated with outside specialists, evaluated internal controls, and offered eligible people complimentary Experian IdentityWorks Credit 3B service. The letter describes credit monitoring, identity restoration, ExtendCARE support after membership, and insurance subject to terms; person-specific duration and enrollment codes appear in individual letters. LeakData does not host incident files or personal records and does not guess the redacted service period.\u003C\u002Fp>","Official Westminster Village Greenwood regulatory letter confirming unauthorized network access and possible access to or acquisition of PII and PHI, with an updated total of 14,386 people",false,"Medium","completed","\u002Fuploads\u002Flogo\u002Fgreenwoodvillagesouth_com.jpg"]