Ransomware victim disclosure
← All victimshsc.mb.ca
Claimed by Incransom · listed 4 hours ago
Status timeline
- ListedOct 11, 2026
- Data leakeddate unknown
At a glance
- Group
- Incransom
- Status
- Data leaked
- Country
- Canada
- Sector
- Healthcare
- Listed on leak site
- Oct 11, 2026
What the group claims
The Health Sciences Centre in Winnipeg, one of the largest medical institutions, was targeted by us that resulted in the largest data breach among healthcare institutions. Our group chose not to completely disrupt the facility’s operations, recognizing the potentially devastating consequences that such an action could have had on patients’ lives and health. Nevertheless, Health Sciences Centre management stated that no sensitive data had been affected, despite having been informed otherwise. The data included, but was not limited to, the following information: Patient medical records: Full name, date of birth, address and phone number Hospital medical record number Diagnoses, medical history, allergies and medications Laboratory results, imaging reports Appointment dates, treatment details and physician information. Employee and healthcare professional information: Names, contact details, dates of birth and employee numbers Employment, payroll and banking information Professional credentials, work schedules and departmental assignments. Financial and insurance information: Billing records and payment histories Insurance or benefits claim information. Confidential hospital documents: Internal emails and staff communications System configurations, network diagrams and security procedures Database backups and exported spreadsheets. We would have very much preferred to avoid making this data breach public, but the management has left us with no other choice.
Sources
Source
Indexed 4 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

