Ransomware victim disclosure
← All victimsPavillon
Claimed by Global Secret Group · listed 3 days ago
Status timeline
- ListedAug 5, 2026
- Data leakeddate unknown
At a glance
- Group
- Global Secret Group
- Status
- Data leaked
- Country
- United States
- Listed on leak site
- Aug 5, 2026
About the victim
AI dossier — public-source company profilePavillon is a nonprofit residential and outpatient addiction treatment center located in the Blue Ridge Mountains of Western North Carolina. Operating for over 30 years with 160 acres of campus, it provides substance use disorder and co-occurring mental health treatment to individuals and families, serving 9,000+ alumni.
- Industry
- Addiction Treatment & Healthcare
- Address
- Mill Spring, North Carolina, United States
- Employees
- 100-200
- Founded
- 1994
Attack summary
Severity: critical — Healthcare facility with confirmed exfiltration of 646 GB of patient data including treatment records, mental health information, and PII. Patient confidentiality in addiction treatment is highly regulated (HIPAA, 42 CFR Part 2); exposure of this scale poses severe regulatory, legal, and personal safety risks to vulnerable populations.Global Secret Group claims to have exfiltrated 646 GB of data (47,950 files, 7,750 folders) from Pavillon. The group has published the data, indicating both encryption and data exfiltration occurred.
Data the group says was taken
AI dossier — extracted from the leak post- Patient treatment records
- Personal identifiable information (PII)
- Mental health and substance use disorder documentation
- Insurance and payment information
- Clinical assessments
- Admission and referral data
What the group claims
Country: Mill Spring, North Carolina, United States | Website: pavillon.org | Revenue: $8.5 Million | Industry: Alcoholism Treatment, Hospitals & Clinics, Healthcare | Employees: 100-200 | Properties: 646 GB (47,950 Files, 7,750 Folders)
Sources
Source
Indexed 3 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

