Ransomware victim disclosure
← All victimsUnknown Philippine Hospital
Claimed by Rhysida · listed 1 day ago
Status timeline
- ListedSep 12, 2026
Current state: Listed for ransom
At a glance
- Group
- Rhysida
- Status
- Listed for ransom
- Country
- Philippines
- Sector
- Healthcare
- Listed on leak site
- Sep 12, 2026
- Data size
- 2.44 TB
- Records
- 3,502,636 files
About the victim
AI dossier — public-source company profileAn unknown Philippine hospital operator. The victim name is a placeholder; the actual hospital identity is not disclosed in the leak post or public sources.
- Industry
- Healthcare
Attack summary
Severity: critical — Confirmed exfiltration of large-scale regulated healthcare data (PHI under Philippine law and equivalent to HIPAA): named patient medical records, cancer diagnoses, birth dates, PhilHealth IDs, neonatal data, plus staff identifiers, passport scans, and sensitive financial records of a medical institution. The 2.44 TB volume and specificity of data categories indicate substantial breach of protected health information.Rhysida claims to have exfiltrated 3.5 million files (~2.44 TB) of hospital data including patient medical records, employee personal information, financial statements, and healthcare identifiers. The group is auctioning the data with a 7-day bidding window and restricting resale.
Data the group says was taken
AI dossier — extracted from the leak post- Patient medical records (PHI) with names and dates
- Surgical pathology and hemodialysis charts
- Cancer-center dossiers with PhilHealth IDs
- Lab tests and cancer-marker results with birth dates
- Neonatal (NICU) data
- Physician registry with cell numbers and PRC licenses
- PhilHealth professional identifiers
- Staff payroll records and salary information
- Employee health insurance files
- Staff passport scans and drug-test results
- Audited financial statements with BIR stamps
- Bank account details across multiple institutions
- Internal audit memos
- SEC stockholders minutes
- Personal cell numbers of leadership
- Owner and CFO personal financial documents
What the group claims
Philippine hospital with patient data (PHI), staff records, financial documents, and leadership personal data. Includes surgical pathology, hemodialysis, cancer center, and NICU data.
The leak post
captured from the group's siteOwner�s documents: employee evaluations, salary rates, bonuses, job offers, family documentsCFO�s documents: client credit reports, bankruptcy records, tax documents, father�s medical records (guardianship court case)Corporate financials: owner�s personal tax return, credit application, signed checks with MICR (BNB Bank)Corporate credit cards, drug testsMedical records, employee health insuranceAnd much more With just 7 days on the clock, seize the opportunity to bid on exclusive, unique, and impressive data. Open your wallets and be ready to buy exclusive data. We sell only to one hand, no reselling, you will be the only owner! 3.502.636 files, total volume ~2.44 TBPatient data (PHI) � name-tagged scans across department shares (surgical pathology, hemodialysis charts, admission records), cancer-center dossiers with PhilHealth IDs, lab quotations incl. cancer-marker tests with birth dates, PhilHealth claims monitoring, neonatal (NICU) dataStaff and professionals � accredited physicians register (cell numbers, PRC licenses, PhilHealth IDs), named payroll workbooks (incl. the affiliated diagnostic center), HR dossiers, staff passport scans, drug-test filesMoney, audit and governance…
Data the group says was taken
- patient health information (PHI)
- medical scans
- hemodialysis charts
- admission records
- cancer center dossiers
- PhilHealth IDs
- lab results
- NICU data
- physician records
- PRC licenses
- payroll records
- HR dossiers
- passport scans
- drug test files
- financial statements
- bank account records
- audit memos
- SEC stockholders minutes
- personal contact information
Screenshot of the leak post

Sources
Source
Indexed 1 day agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

