Step By Step, Inc. Data Breach Exposes Sensitive Personal and Health Information

Published: 3 October 2026
Non-profit data breach illustration
Breach Discovery: Not Publicly DisclosedBreach Notification: Not Publicly Disclosed

A ransomware group known as Storm claims it breached Step By Step, Inc., a Pennsylvania nonprofit serving over 2,000 individuals with disabilities and behavioral health needs. The organization has not confirmed the incident publicly. If you received services from or worked for this nonprofit, monitor your credit reports and watch for suspicious communications right away.

CompanyStep By Step, Inc.
IndustryNon-profit
Data Types ExposedFull Names and Contact Information, Social Security Numbers, Dates of Birth, Health and Behavioral Health Records, Disability Status and Treatment Information, Employment Records, Insurance or Billing Information
People AffectedNot Publicly Disclosed
Attack MethodRansomware
Regulators NotifiedNot Publicly Disclosed

Were you affected by this breach?

You may be owed compensation.

Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.

Check if you qualify — free review

What Happened in the Step By Step, Inc. Data Breach?

A ransomware group calling itself Storm has claimed responsibility for a cyberattack on Step By Step, Inc., a Pennsylvania-based nonprofit human services organization. The group listed the organization on its dark web leak site, asserting that it accessed internal systems and data. As of now, Step By Step, Inc. has not publicly confirmed this incident.

Because this report stems from a ransomware group’s own claim, many details remain unverified. The exact timeline of the alleged Step By Step, Inc. data breach, including when attackers first gained access, has not been publicly disclosed. Similarly, the specific method the Storm group used to breach the network is not yet known.

At this stage, there is no public statement describing an internal investigation, forensic review, or remediation effort. As a result, affected individuals should treat this as an unconfirmed but credible claim until Step By Step, Inc. issues an official statement. This article will be updated if the organization releases further information.

Who was affected?

Step By Step, Inc. provides community-based services to more than 2,000 individuals across over a dozen Pennsylvania counties. Because of the nature of its work, the people potentially affected likely include clients with intellectual and physical disabilities, autism, mental health conditions, and substance use disorders.

In addition to clients, current and former employees could also be affected, since organizations of this size typically store staff records alongside client files. The exact number of individuals impacted by this incident has not been publicly disclosed. Given the vulnerable populations this nonprofit serves, including potentially minors in family support programs, the stakes for any real exposure are especially high.

The organization operates in Wilkes-Barre and surrounding counties, so the geographic scope of affected individuals is likely concentrated in northeastern Pennsylvania. However, family members, guardians, and community partners connected to client files could also be indirectly affected.

What Information Was Potentially Exposed?

Because Step By Step, Inc. has not confirmed the incident, the exact data types involved in this alleged breach are not fully known. However, based on the nature of services this nonprofit provides, the kinds of records typically held by human services organizations like this one may include the following categories.

  • Full names and contact information
  • Social Security numbers
  • Dates of birth
  • Health and behavioral health records
  • Disability status and treatment information
  • Employment records for staff
  • Insurance or billing information

If this data was in fact accessed, the risk to affected individuals could be significant. Social Security numbers combined with dates of birth and names create a strong foundation for identity theft. Criminals could use this combination to open new credit lines, file fraudulent tax returns, or apply for loans in someone else’s name.

In addition, exposed health and behavioral health records carry their own distinct risks. This type of information could be used for medical identity theft, insurance fraud, or targeted scams that exploit a person’s specific health condition. Because many of the organization’s clients belong to vulnerable populations, any leaked health data could also lead to privacy harms beyond financial fraud, including social stigma or discrimination.

What is the company doing?

Step By Step, Inc. has not released a public statement confirming or responding to the Storm group’s claims. Therefore, no specific remediation steps, credit monitoring offers, or formal notifications can be confirmed at this time.

Because this remains an unconfirmed claim from a ransomware group’s leak site, any internal investigation or protective measures the organization may be taking are not yet known. Affected individuals should watch for official communication directly from Step By Step, Inc. in the coming weeks. If the organization issues a notification letter or public statement, this article will be updated to reflect confirmed facts.

What Should Affected Individuals Do?

Monitor Your Credit Reports

Anyone who has received services from or worked for Step By Step, Inc. should check their credit reports closely. You can request free reports from all three major credit bureaus at AnnualCreditReport.com. Reviewing these reports regularly helps you catch unauthorized accounts or inquiries early.

Because Social Security numbers may have been involved, this step is especially important. Look for accounts you did not open, unfamiliar addresses, or unexpected credit inquiries. If you spot anything suspicious, report it to the credit bureau immediately and consider filing a police report.

Consider a Credit Freeze or Fraud Alert

If you believe your Social Security number may have been exposed, placing a credit freeze is one of the strongest protective steps available. A freeze blocks new creditors from accessing your credit file, which makes it much harder for identity thieves to open accounts in your name.

Alternatively, a fraud alert requires lenders to take extra verification steps before approving new credit. This option is less restrictive than a freeze but still offers meaningful protection. Both tools are free, and you can request them directly through any of the three credit bureaus.

Watch for Health-Related Identity Fraud

Because this nonprofit provides behavioral health, autism, and substance use disorder services, exposed health records carry unique risks. Medical identity theft can lead to incorrect information in your medical file, which could affect future treatment decisions.

As a precaution, review any insurance statements or medical bills for services you do not recognize. If you notice unfamiliar claims, contact your insurance provider right away. Keeping copies of your explanation of benefits statements can help you track discrepancies over time.

Stay Alert for Phishing Attempts

Following any data breach, scammers often use stolen information to craft convincing phishing emails or phone calls. Be cautious of messages claiming to be from Step By Step, Inc., healthcare providers, or financial institutions that ask for personal details.

Instead of clicking links in unexpected emails, verify the sender by contacting the organization directly through a known phone number or website. This simple habit can prevent scammers from tricking you into revealing additional sensitive information.

Consult a Data Breach Attorney

If you believe your personal or health information was compromised in this incident, speaking with a data breach attorney can help clarify your legal options. Many attorneys offer free case evaluations and can explain whether you may qualify to join a class action.

Because laws around data breach liability vary, an attorney can also help you understand applicable deadlines for filing a claim. Acting sooner rather than later ensures you do not miss any relevant filing windows.

Get a Free Case Review

Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.



Related Data Breaches

Check other recent data breach notifications →