Ransomware victim disclosure
← All victimsLa Red Health Center
Claimed by Karakurt · listed 3 years ago
Status timeline
- Listed
Apr 27, 2023
- Data leaked
At a glance
- Group
- Karakurt
- Status
- Data leaked
- Country
- United States
- Sector
- Healthcare
- Listed on leak site
- Apr 27, 2023
- Data size
- 79 GB
About the victim
AI dossier — public-source company profileLa Red Health Center is an integrated community health center operating multiple locations in Delaware (Georgetown, Seaford, and Milford), providing medical, mental health, and dental care to underserved populations. It operates as a Federally Qualified Health Center receiving HHS funding with Federal Public Health Service deemed status. Services include pediatric care, women's health, behavioral health, substance use recovery, and a discount pharmacy program.
- Industry
- Federally Qualified Health Center (FQHC) / Community Health
- Address
- 21444 Carmean Way, Georgetown, DE 19947
Attack summary
Severity: critical — Confirmed exfiltration and publication of 79 GB of data from a healthcare provider, explicitly including medical records with diagnoses (HIPAA-protected PHI) and PII for employees and students at scale, meeting the threshold for critical severity.Karakurt claims to have exfiltrated 79 GB of data from La Red Health Center, including financial documents, medical records with diagnoses, and personal information of employees and students. The disclosure status is listed as data_published, indicating the stolen data has been released.
Data the group says was taken
AI dossier — extracted from the leak post- Financial documents
- Medical records with diagnoses
- Employee personal information
- Student personal information
What the group claims
La Red Health Center provides an outreach programs help reach undeserved populations and enhance access to quality health care. We have 79GB from them: lots of financial documents, medical records with diagnosis, their employee and students personal information.
Sources
Source
Indexed 3 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
