Ransomware victim disclosure
← All victimsHealth Carousel
Claimed by Direwolf · listed 7 days ago
Status timeline
- ListedAug 10, 2026
- Data leakeddate unknown
At a glance
- Group
- Direwolf
- Status
- Data leaked
- Country
- Philippines
- Sector
- Healthcare
- Listed on leak site
- Aug 10, 2026
About the victim
AI dossier — public-source company profileHealth Carousel is a healthcare staffing and workforce management solutions provider based in Ohio, USA. Founded in 2004, the company specializes in nursing and allied health staffing, positioning itself as an employer-focused alternative to traditional contract labor models. They have served over 15 million patients and operate both domestic US travel nursing placements and international healthcare recruitment.
- Industry
- Healthcare Staffing & Workforce Management
- Founded
- 2004
Attack summary
Severity: high — Confirmed data exfiltration with GDPR-restricted designation indicates personal data of healthcare professionals and candidates at scale. Healthcare sector combined with international staffing operations elevates sensitivity. Published status confirms data disclosure occurred.The direwolf group claims to have breached Health Carousel and published exfiltrated data. The leak post indicates GDPR-restricted data was accessed, suggesting personal information of individuals within their scope of operations.
Data the group says was taken
AI dossier — extracted from the leak post- Personal identifiable information (PII)
- Healthcare professional records
- Employment/staffing data
- Potentially international candidate information
What the group claims
Business Services · Ohio
The leak post
captured from the group's site```
{"article":{"id":74,"title":"Health Carousel","content":"","summary":"{\"company_name\":\"Health Carousel\",\"company_website\":\"https://www.healthcarousel.com\",\"industry\":\"Business Services · Ohio\",\"gdpr_restricted\":true,\"data_size\":\"\"}","country":"US","file_browser_url":"","data_types":"15,16,19,20,22,25,30","countdown_end":"2026-08-31T23:59:00Z","status":"","view_count":0,"publish_time":"2026-08-10T18:38:34.541408254Z","created_at":"2026-08-10T18:38:34.541408314Z","updated_at":"2026-08-10T18:38:34.541408314Z"}}
```Sources
Source
Indexed 7 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

