Ransomware victim disclosure
← All victimsGibson Area Hospital & Health Services
Claimed by Wallstreet · listed 4 hours ago
Status timeline
- ListedSep 29, 2026
- Data leakeddate unknown
At a glance
- Group
- Wallstreet
- Status
- Data leaked
- Country
- United States
- Sector
- Healthcare
- Listed on leak site
- Sep 29, 2026
About the victim
AI dossier — public-source company profileGibson Area Hospital & Health Services is a nonprofit community hospital located in Gibson City, Illinois. It provides emergency care, inpatient and outpatient treatment, diagnostic testing, rehabilitation, primary care, and obstetric services.
- Industry
- Healthcare - Community Hospital
- Address
- Gibson City, Illinois, US
Attack summary
Severity: high — Confirmed data publication from a healthcare provider; healthcare sector handles regulated PII (patient records, medical histories) at scale. Lack of specific proof count or detailed inventory limits classification to 'high' rather than 'critical', but the sector and disclosure status warrant elevated severity.The Wallstreet group claims to have attacked Gibson Area Hospital & Health Services. The leak post indicates data has been published, though specific details on exfiltration versus encryption, or the nature of compromised data, are not provided in the excerpt.
Data the group says was taken
AI dossier — extracted from the leak post- Healthcare records
- Patient data
- Operational systems
What the group claims
Gibson Area Hospital & Health Services is a nonprofit community hospital located in Gibson City, Illinois. It provides a range of healthcare services, including emergency care, inpatient and outpatient treatment, diagnostic testing, rehabilitation, primary care, and services for women and newborns
Source
Indexed 4 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

