St Theresa Catholic Church Data Breach

Alleged

Ransomware claim involving St Theresa Catholic Church

Published: Aug 6, 2026 Orova
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
St Theresa Catholic Church
Industry
Non-profit
Threat Actor
Orova
Date of Incident
Aug 6, 2026

Executive Summary

St Theresa Catholic Church, a religious organization located in the United States, has been identified as a victim of the Orova ransomware group. The listing on the group’s dark web portal was published on August 6, 2026, and was detected by SOCRadar’s Dark Web Monitoring service. Organizations like St Theresa Catholic Church, which often rely on volunteer IT management and have limited dedicated security resources, are frequently targeted by ransomware groups. This incident is particularly notable as it was one of nine entries published by Orova on the same date and marked the second congregation listed in that batch, highlighting the group’s activity against community-focused entities. In the 60 days preceding this listing, Orova had claimed a total of 34 victims. The ransomware group demonstrates a consistent pattern of targeting the ‘other’, healthcare, and professional services sectors. Geographically, the United States, Hong Kong, and Taiwan are the most frequently targeted countries. Similar to St Theresa Catholic Church, other recent victims listed by Orova that share characteristics such as being small US community organizations include First Baptist Church of Belleview, Stonecrest POA, Stoneybrook West Master Association Inc, and Gemstone UK. This pattern suggests that Orova’s focus is on volume of victims, particularly smaller US community organizations, rather than necessarily high-profile targets, indicating that leak-site activity does not always equate to the significance of the victim.

Technical Analysis

SOCRadar’s analysis of St Theresa Catholic Church’s domain, mystcc.org, using stealer-log telemetry returned no matching records within the queried dataset. It is crucial to understand that a null result from this specific query does not conclusively indicate that the organization is unaffected by a compromise. The telemetry dataset is paginated and represents only a slice of available data. Potential exposures tied to alternate or associated domains, shared infrastructure within a diocese, or the use of personal email aliases by staff and volunteers would not be captured by this query. Since parishes often operate within a larger diocesan IT infrastructure, the relevant identity namespace for a compromise might not even be the parish’s own domain. For ransomware operations like those conducted by the Orova group, infostealer-harvested credentials represent a significant and well-documented initial access vector. Threat actors or initial access brokers routinely source credential logs from underground marketplaces, validate corporate account access, and subsequently use these credentials to gain entry into systems such as Microsoft 365, VPNs, or remote-access portals. After establishing a foothold, ransomware is deployed. The absence of evidence in the stealer-log query does not preclude this scenario. Credentials may have been exposed in data feeds not included in this analysis, they might have been harvested and subsequently rotated before being indexed, or they could have been obtained using personal email aliases associated with organizational accounts. Given these findings, cybersecurity teams should prioritize continued monitoring of dark web and stealer-log feeds for any emerging information related to St Theresa Catholic Church or its associated entities. Proactive credential hygiene checks, including regular password rotation and a thorough review of multi-factor authentication configurations, are essential. It is also recommended to review activity logs for Microsoft 365, VPNs, and remote-access solutions. Monitoring for any potential compromise through alternate corporate domains or diocesan infrastructure should be maintained, as a null query result does not serve as an indicator of complete security.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.