
The LGBTQ Center of Orange County revealed that a data security incident it experienced last year compromised the sensitive personal information of more than 75,000 individuals.
The LGBTQ Center of Orange County (LGBTQ Center OC) is a nonprofit organization based in Santa Ana, California, that provides support, advocacy, and community services for LGBTQ+ individuals and their families across Orange County. Founded in 1971 and incorporated as a nonprofit in 1975, it is one of the oldest LGBTQ community centers in the United States.
In a data security incident notice published on its website, LGBTQ Center of Orange County said that on December 26, it identified unauthorised access within its internal network. The organisation immediately launched an investigation, with assistance from external cyber security experts, to determine the nature and scope of the incident.
It also took steps to secure the affected systems and notified relevant law enforcement authorities about the incident.
“Following the completion of the investigation, it was determined that some files may have been accessed or removed by the unauthorised individual(s) between approximately December 25, 2025 and December 26, 2025,” LGBTQ Center of Orange County said.
The compromised data included names, dates of birth, Social Security numbers, diagnosis information, prescription information, medical history and treatment information, medical record numbers, health insurance information, driver’s license numbers, government identification numbers, state identification numbers, passport numbers, taxpayer identification numbers, financial account information, biometric identifiers, financial account information, and payment card information.
The incident was reported to the U.S. Department of Health and Human Services, where LGBTQ Center OC said it has identified at least 75,532 individuals affected by the incident.
The organisation has advised all affected individuals to regularly monitor their credit reports, account and benefit statements and report any suspicious activity to law enforcement authorities, including the police and the state attorney general.
On January 28, 2026, the INC Ransom ransomware group claimed responsibility for the cyber attack on the LGBTQ Center of Orange County and listed the organisation as a victim on its data leak site. The group claimed it had exfiltrated confidential data from the organisation and threatened to publish the entire stolen dataset unless its ransom demands were met.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543