Unverified claim. Ransomware group Qilin added GOP to its leak site on July 24, 2026, claiming theft of internal data (Ransomware.live, GalaxyWarden).
The organization had not confirmed the listing. Public mirrors did not publish a donor or staff headcount.
Why donors should care anyway
Political databases often hold contact and donation history. Even without a confirmed dump, phishing that cites party branding spikes after leak-site posts.
Action items
- Rotate passwords used on GOP/RNC donation portals and enable authenticator 2FA.
- Ignore “verify your donor account” emails that are not from domains you typed yourself.
- Wait for an official party or regulator notice before assuming specific records are confirmed stolen.