Ransomware victim disclosure
← All victimsMorula IVF
Claimed by Everest · listed 5 hours ago
Status timeline
- ListedSep 25, 2026
- Data leakeddate unknown
At a glance
- Group
- Everest
- Status
- Data leaked
- Country
- South Africa
- Sector
- Healthcare
- Listed on leak site
- Sep 25, 2026
About the victim
AI dossier — public-source company profileMorula IVF is a network of fertility clinics operating in Indonesia, specializing in in vitro fertilization (IVF) and assisted reproductive technologies. The clinic network provides fertility consultations, gamete preservation, and infertility treatments across multiple Indonesian cities.
- Industry
- Reproductive Medicine & Fertility Services
Attack summary
Severity: high — Fertility clinic data includes highly sensitive PII and protected health information (medical records, reproductive history, genetic material records). Exfiltration of such data at a healthcare organization scale presents significant privacy and regulatory risk, even without explicit proof files advertised.The Everest group claims to have exfiltrated data from Morula IVF. The leak post does not specify what data categories were taken or whether encryption occurred.
Data the group says was taken
AI dossier — extracted from the leak post- Patient medical records
- Fertility treatment data
- Personal identifying information
Original description
AI-summarised, not from the leak postMorula IVF is a network of fertility clinics operating in Indonesia, specializing in in vitro fertilization (IVF) and other assisted reproductive technologies. It operates within the healthcare industry, specifically reproductive medicine, offering services such as fertility consultations, egg and sperm preservation, and infertility treatments. The company has multiple clinic locations across major Indonesian cities, serving patients seeking fertility treatment options.
Sources
Source
Indexed 5 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

