Ransomware victim disclosure
← All victimsRood & Riddle Equine Hospital
Claimed by Storm · listed 4 days ago
Status timeline
- ListedAug 14, 2026
- Data leakeddate unknown
At a glance
- Group
- Storm
- Status
- Data leaked
- Country
- United States
- Sector
- Healthcare
- Listed on leak site
- Aug 14, 2026
About the victim
AI dossier — public-source company profileRood & Riddle Equine Hospital is a multi-location equine veterinary practice founded in 1986 in Lexington, Kentucky by veterinarians William Rood and Thomas Riddle. The facility operates three branches (Lexington, Saratoga Springs, and Wellington) and provides comprehensive medical, surgical, diagnostic, and therapeutic services for horses, including care for Thoroughbreds and sport horses.
- Industry
- Equine Veterinary Medicine & Surgery
- Address
- 2150 Georgetown Road, Lexington, KY 40511, United States
- Employees
- 201-500
- Founded
- 1986
Attack summary
Severity: medium — Data published status confirmed, but no proof files advertised and no specific data categories disclosed. Healthcare sector (veterinary records may include client PII and animal/patient information), but scope of exposure unknown.The Storm group claims to have breached Rood & Riddle Equine Hospital. The leak post does not specify whether data was exfiltrated, encrypted, or both, nor does it detail what categories of data are at stake.
What the group claims
Rood & Riddle Equine Hospital was established in Lexington, Kentucky in 1986 as a partnership between veterinarians William Rood and Thomas Riddle. The facility offers a range of services for the treatment of horses. They have cared for many famous Thoroughbreds both at the racetrack and on the farm. They also provide support for other equine sporting events such as the 2010 FEI World Equestrian Games held in Lexington. Rood & Riddle operates branches in Saratoga Springs, New York and Wellington, Florida. The company headquarters is located in 2150 Georgetown Road, Lexington, KY 40511, United States. 201-500 Employees
Sources
Source
Indexed 4 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

