Ransomware victim disclosure
← All victimsUnknown County/Medical Entity
Claimed by Rhysida · listed 40 minutes ago
Status timeline
- ListedOct 2, 2026
Current state: Listed for ransom
At a glance
- Group
- Rhysida
- Status
- Listed for ransom
- Country
- United States
- Sector
- Government / Healthcare
- Listed on leak site
- Oct 2, 2026
- Data size
- 2.6 TB
- Records
- 814,500 files; 721 background-check dossiers; 47,602 medical-assistance files
About the victim
AI dossier — public-source company profileAn unknown US county or municipal government entity with integrated healthcare operations, including jail facilities and medical assistance programs. The victim manages law enforcement records, detention operations, and public health services.
- Industry
- Government / Healthcare
Attack summary
Severity: critical — Confirmed exfiltration of highly regulated and sensitive data at scale: medical records (including strict 42 CFR Part 2 methadone clinic files), criminal case files with juveniles and victims, SSNs at scale across multiple datasets (721+ background checks, thousands in HOA/banking contexts, medical-assistance files), banking credentials, law enforcement intelligence, and jail records. Multiple categories of regulated PII and protected health information (PHI) create acute harm and compliance vioRhysida claims to have exfiltrated 2.6 TB of data across multiple stolen datasets: criminal case files from a law office (~206 GB of bodycam/discovery), HOA financial and personal records (~1.84 TB with SSNs and banking credentials), and county government records including jail intelligence, payroll, medical faxes, background checks, and medical-assistance files with PII.
Data the group says was taken
AI dossier — extracted from the leak post- Criminal defense case files with client names and charges
- Bodycam video and police discovery (~206 GB)
- 911 recordings and jail calls
- Social Security numbers (multiple contexts)
- Banking credentials and ACH routing/account numbers
- Medical records and methadone clinic files (42 CFR Part 2)
- Patient names and diagnoses from medical faxes
- Driver licenses, Green Cards, tax forms
- County payroll and HR records
- Jail gang-intelligence database
- Background-check dossiers
- Home purchase settlements and mortgage data
What the group claims
Background-check dossiers with full SSNs, medical faxes with patient names and diagnoses, methadone clinic records under 42 CFR Part 2, medical-assistance files with driver licenses, Green Cards, SSN cards, tax forms and bank data, county payroll registers, HR memos, contracts, pension and discipline databases, and jail gang-intelligence files.
The leak post
captured from the group's siteWith more than 40 employees, the agency manages national and international online projects of companies from a wide range of industries. Based in Berlin, Dresden, Munich and Cologne, has been a specialist in online marketing for more than twelve years. With just 7 days on the clock, seize the opportunity to bid on exclusive, unique, and impressive data. Open your wallets and be ready to buy exclusive data. We sell only to one hand, no reselling, you will be the only owner! [Law Offices of R. David Williams, P.A.](https://www.dwilliamslaw.com) Contents. A complete dossier of the firm's criminal defense practice covering ~175+ clients: felonies (an undercover sex sting involving a minor - Ramirez; domestic violence robbery - Valderrama, involving a 4-year-old child; felony DUI - Segula; fraud - B. Williams), a core caseload of ~10 DUI matters (including an arrest at breath readings of 0.011 and SCRAM alcohol monitoring), violations of probation (VOP), FDLE expungement packets with FD-258 fingerprint cards, a 'red flag' Risk Protection Order (RPO), 2 clients in ICE custody, and a material witness under GPS monitoring for 3+ years. Attorney fees range from $750 to $25,000. The case fil…
Data the group says was taken
- background check dossiers
- SSNs
- medical faxes
- patient diagnoses
- methadone clinic records
- driver licenses
- Green Cards
- tax forms
- bank data
- payroll registers
- HR records
- pension records
- discipline records
- gang intelligence files
Screenshot of the leak post

Sources
Source
Indexed 40 minutes agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

