Ransomware victim disclosure
← All victimsMenninger Clinic
Claimed by Blacksuit · listed 2 years ago
Status timeline
- ListedSep 24, 2024
- Data leakeddate unknown
At a glance
- Group
- Blacksuit
- Status
- Data leaked
- Country
- United States
- Sector
- Healthcare
- Listed on leak site
- Sep 24, 2024
About the victim
AI dossier — public-source company profileThe Menninger Clinic is a nationally ranked mental health and addiction treatment provider based in Houston, Texas. They offer inpatient and outpatient services for adults, young adults, and children & adolescents, with expertise in treating serious mental illness, addiction, trauma, and related disorders.
- Industry
- Mental Health & Addiction Treatment
- Address
- Houston, Texas, United States
Attack summary
Severity: critical — Healthcare provider with confirmed data exfiltration of unknown scope; likely includes protected health information (PHI) and employee PII. HIPAA-regulated entity. Disclosure status confirms data published.Blacksuit claims to have exfiltrated data from Menninger Clinic after the organization failed to respond to ransom demands. The group issued a 72-hour ultimatum before beginning publication of stolen data, though the specific nature and scope of exfiltrated information is not detailed in the post.
Data the group says was taken
AI dossier — extracted from the leak post- Employee records
- Patient health information
- Personal identifiable information
What the group claims
Despite repeated attempts to contact menningerclinic.org we were ignored. The negligence of the management of this organization surprised us. This leaves us with no choice but to start publishing data. Menningerclinic.org has 72 hours to contact us and resolve the situation without exposing their employees to the problems they will face.
Sources
Source
Indexed 2 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

