Recovery Cafe Data Breach Exposes Client Health and Personal Records

Published: 9 September 2026
Non-profit data breach illustration
Breach Discovery: Not Publicly DisclosedBreach Notification: September 2026

Recovery Cafe, a Seattle nonprofit supporting people in recovery from addiction and trauma, suffered a ransomware attack claimed by the Safepay group, notified in September 2026. Client and possibly staff data, including health and personal information, may have been exposed. Affected individuals should monitor credit reports and watch for phishing attempts immediately.

CompanyRecovery Cafe
IndustryNon-profit
Data Types ExposedFull Names, Contact Information, Health and Recovery Program Records, Substance Use or Mental Health Treatment Details, Dates of Birth, Social Security Numbers, Emergency Contact Information
People AffectedNot Publicly Disclosed
Attack MethodRansomware
Regulators NotifiedNot Publicly Disclosed

What Happened in the Recovery Cafe Data Breach?

Recovery Cafe, a Seattle-based nonprofit that supports people healing from trauma, addiction, and homelessness, has confirmed a ransomware attack on its computer network. A group known as Safepay has claimed responsibility for the intrusion. The Recovery Cafe data breach raises serious concerns for the vulnerable community the organization serves.

Details about exactly when the intrusion began have not been publicly disclosed. However, the attack falls under a broader pattern of ransomware groups targeting healthcare and social service organizations. These groups often infiltrate networks quietly before deploying malicious software or extracting files.

According to available information, the Safepay group gained unauthorized access to Recovery Cafe’s systems and potentially copied sensitive files before or during the attack. This tactic, known as double extortion, lets attackers threaten to leak stolen data even if a ransom is paid. As a result, victims face exposure risk regardless of any ransom negotiation outcome.

Recovery Cafe’s notification regarding this incident came in September 2026. Since then, the organization has reportedly worked to determine the scope of the intrusion. Because forensic investigations into ransomware attacks can take weeks or months, additional details may still emerge as the review continues.

Who was affected?

The population affected by this breach likely includes current and former Recovery Cafe clients, known as “members” within the organization’s community-based recovery model. In addition, staff, volunteers, and possibly donors could also be impacted if their personal data was stored on the compromised systems.

The exact number of individuals affected has not been publicly disclosed. Because Recovery Cafe serves people recovering from trauma, addiction, and homelessness, many affected individuals may be especially vulnerable to the stress and stigma that can come with a data exposure of this nature.

Given the organization’s founding in Seattle and its focus on community-based recovery programs, the affected population is likely concentrated in the Pacific Northwest. Nonetheless, individuals who moved away from the area after using Recovery Cafe’s services could also be impacted.

What Information Was Potentially Exposed?

While a complete, itemized list of exposed data fields has not been publicly released, ransomware attacks on healthcare and social service organizations commonly involve theft of sensitive personal and health-related records. Based on the nature of Recovery Cafe’s services, the following categories of information may have been involved.

  • Full names
  • Contact information such as addresses and phone numbers
  • Health and recovery program records
  • Substance use or mental health treatment details
  • Dates of birth
  • Possible Social Security numbers
  • Emergency contact information

If any of this information was indeed accessed, affected individuals could face a heightened risk of identity theft. Criminals often use stolen names, birth dates, and Social Security numbers to open fraudulent credit accounts or file false tax returns.

Beyond financial fraud, exposure of addiction or mental health treatment records carries a unique risk. This type of information is highly sensitive, and its disclosure could lead to discrimination, harassment, or emotional distress for those affected. Because Recovery Cafe serves a vulnerable population, this risk deserves particular attention.

What is the company doing?

In response to the attack, Recovery Cafe has reportedly taken steps to investigate the intrusion and secure its systems. Typically, this involves engaging cybersecurity specialists to determine which files were accessed and to close any remaining vulnerabilities.

Furthermore, Recovery Cafe appears to have begun notifying affected individuals and relevant authorities about the incident, consistent with the September 2026 notification timeline. Organizations facing similar attacks often offer credit monitoring or identity protection services to those whose sensitive data was compromised, though it is unclear whether Recovery Cafe has extended this specific offer.

As the investigation continues, Recovery Cafe may release additional updates. In the meantime, affected individuals should watch for direct communication from the organization regarding their specific data exposure.

What Should Affected Individuals Do?

Monitor Your Credit Reports

Anyone connected to Recovery Cafe should check their credit reports regularly for unfamiliar activity. This includes new accounts, credit inquiries, or changes to your name and address that you didn’t authorize.

You can request a free credit report from each of the three major credit bureaus once a year through AnnualCreditReport.com. Because fraud can take time to surface, checking your reports every few months for the next year is a wise precaution.

Consider a Fraud Alert or Credit Freeze

If Social Security numbers were among the exposed data, placing a fraud alert or credit freeze on your credit files is a strong protective step. A fraud alert requires lenders to verify your identity before opening new credit, while a credit freeze blocks access to your credit file entirely.

Both options are free and can be requested directly through Equifax, Experian, and TransUnion. Because a freeze offers stronger protection, it’s often the better choice if you suspect your Social Security number may have been exposed.

Protect Sensitive Health and Recovery Records

Because this breach may involve treatment or recovery program details, affected individuals should be alert to potential misuse of health information. For example, scammers sometimes use stolen medical details to file fraudulent insurance claims or obtain prescriptions in someone else’s name.

If you notice unfamiliar medical bills, insurance statements, or collection notices, address them right away. Contacting your insurance provider and requesting an explanation of benefits can help you spot unauthorized claims tied to your identity.

Stay Alert for Phishing Attempts

Following a data breach, affected individuals often become targets of phishing emails, texts, or phone calls that pretend to be from a trusted organization. These messages may ask you to confirm personal details or click suspicious links.

Always verify the sender before responding to any unexpected message referencing Recovery Cafe or this breach. In addition, avoid clicking on links from unfamiliar sources, and contact the organization directly using a verified phone number if you have questions.

Consult a Data Breach Attorney

If you believe your personal or health information was compromised in this incident, speaking with a data breach attorney can help clarify your legal options. Many attorneys offer free consultations to evaluate whether you may be entitled to compensation.

Because deadlines for filing legal claims vary by state, seeking guidance sooner rather than later is generally advisable. An attorney can also help you understand what documentation to keep in case further fraud occurs.



Related Data Breaches

View the full list of tracked data breaches →