Northwestern Community Services Board Data Breach Affects 21,856 Individuals

Published
June 9, 2025
Updated
July 8, 2025
Northwestern Community Services Board Data Breach Affects 21,856 Individuals
Northwestern Community Services
Types of INFORMATION affected
  • Names
    Names
  • Social security numbers
    Social Security Numbers
  • Dates of birth
    Dates of Birth
  • Addresses
    Addresses
  • Government IDs
    Government IDs
  • Medical Information
    Medical Info
  • Financial Info
    Financial Info

Affected by the

Northwestern Community Services

data breach?

Join the Lawsuit

It's free to join. 

Banner advertisement for ExpressVPN to take control of your online security

Claim Depot may receieve a commission from links on this page

Northwestern Community Services Board (NWCSB), a public provider of behavioral health services in Virginia’s Shenandoah Valley, has experienced a data breach. The incident, discovered on August 8, 2024, affected 21,856 individuals in the United States, exposing both personally identifiable information (PII) and protected health information (PHI).

The breach was the result of a ransomware attack carried out by the group known as BLACK SUIT, which claimed responsibility for the attack on August 24, 2024. The attack was posted on the Tor network, a platform for ransomware groups to publicize their crimes and pressure organizations into paying ransoms.

NWCSB disclosed the breach to the U.S. Department of Health and Human Services on May 29, 2025. The company also posted a Notification of Data Security Incident on its own website.

The data breach was disclosed to the Massachusetts and Maine Attorney Generals' offices beginning on July 7, 2025. Affected individuals include six Massachusetts residents and seven from Maine.

Patient and employee information compromised may include names, medical history and treatment information, health insurance details, and financial information.

Northwestern Community Services Board's response

In response to the breach, Northwestern Community Services Board has taken steps to comply with regulatory requirements and notify affected individuals.

If you received a notification or believe you may be affected by this breach, it is important to:

  • Carefully review any notice or communication you receive from Northwestern Community Services Board.
  • Review your account statements and explanation of benefits forms for suspicious activity.
  • Monitor your credit reports for any unauthorized accounts or changes.
  • Consider placing a fraud alert or credit freeze with the major credit bureaus.

For more details about the company and its services, visit the Northwestern Community Services Board website.

Protect Your Data

A breach notice means your personal details could be circulating far beyond the organization involved. One practical step is continuous monitoring: services such as Identity Defender (included with an ExpressVPN subscription) can automatically check dark-web markets, flag new credit-file activity, and request removal of your information from data-broker sites.

This kind of “early-warning system” can’t undo a breach, but it can help you spot misuse quickly and limit further exposure. ExpressVPN is offering 61% off, risk-free for 30 days, with ID Theft Insurance included and no extra cost for those who sign up for one or two years.

Notice Letter

This browser does not support inline PDFs. Please download the PDF to view it: Download PDF

Consumers Notification date
July 07, 2025
Date of Breach
Breach Discovered Date
May 12, 2025
Total People Affected
15663
Information Types Exposed
  • Medical Records
  • Financial information
  • Health insurance information
  • Medical history and treatment information
  • Names
  • Social security numbers
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image