Ransomware victim disclosure
← All victimsBerlin, Germany
Claimed by Rhysida · listed 3 days ago
Status timeline
- ListedAug 28, 2026
- Data leakeddate unknown
At a glance
About the victim
AI dossier — public-source company profileA clinic or medical practice operating in Berlin, Germany with a large patient base and comprehensive electronic health records system spanning decades of operations.
- Industry
- Healthcare & Medical Services
- Address
- Berlin, Germany
Attack summary
Severity: critical — Confirmed exfiltration of large-scale protected health information (PHI), personal identification data (SSNs, passports), and financial records from a healthcare provider. The disclosure of 160,870+ patient records with unencrypted EHR data triggers GDPR and medical privacy regulations.Rhysida claims to have exfiltrated 9,056,196 files (3.28 TB) from the clinic's databases, including patient records, diagnoses, EHR scans, and personal identification data, as well as financial and employment records. The group is soliciting bids on the stolen data with a 7-day deadline.
Data the group says was taken
AI dossier — extracted from the leak post- Patient records (160,870 patients)
- Medical diagnoses (4.18 million records)
- Electronic health records (7.6 million unencrypted scans)
- Social Security numbers
- Passport data
- Personal identification documents
- Financial statements
- Employee salaries
- Tax records
What the group claims
Berlin, Germany Total capacity 5.79 TBArchive scale: ~1.44 million files scanned; by category � Maps/Geo 124,823, Legal/complaints 77,939, Financial 55,553, Contracts 46,522, HR 27,299,Government supervisory 13,142, Confidential 11,777, Infrastructure 8,110, Passwords 5,941, Health 2,738, Contacts 2,287.PII leak: 16,389 e-mails, 11,963 phone numbers, 12,076 individuals, 148 IBANs.Credentials in plaintext: Geb�udeAtlas, the ePayment PAYONE payment database, personal 'password safes' (danz, kramell � Z_ADMIN database accounts, franssen), leadership credentials.Disciplinary proceedings: the ANDERSON case (432 files, 2025�2026, lawsuit at VG Berlin administrative court), the politically motivated misconduct case involving the LKA Staatsschutz (state security police), the forestry cases BLAUTH/M�LLER/FIELICKE.State secrets: Bundesrat committee protocols with declassification correspondence, Geheimschutz (classified-material handling) data.Passports/IDs (recent, from personnel files and GI-Vertraulich).KRITIS: vulnerability analyses of Berlin's water supply.Mass personal data: Personalakten (personnel files) >5,000, Convotis payroll, OWi (administrative-offence) files >5,000, Postbuch SQL dumps 2020�2026, PST archives, leadership private data (IBANs, ID cards, Behrendt's bank card).NDA: 3,226 documentsLegal violation map (GDPR Art. 32/9/33, VSA/StGB upon VS classification confirmation, BSIG/KRITIS) More
The leak post
captured from the group's site9,056,196 files3.28 TBLarge SQL databases containing the clinic's entire lifetime of information.Major databases:160,870 patients4.18 million diagnoses7.6 million unencrypted EHR scansSSN, passports, and other personal data.Financial statements, salaries, taxes.Dear customers, please submit your requests�there are plenty of files here that can be monetized. With just 7 days on the clock, seize the opportunity to bid on exclusive, unique, and impressive data. Open your wallets and be ready to buy exclusive data. We sell only to one hand, no reselling, you will be the only owner! 9,056,196 files3.28 TBLarge SQL databases containing the clinic's entire lifetime of information.Major databases:160,870 patients4.18 million diagnoses7.6 million unencrypted EHR scansSSN, passports, and other personal data.Financial statements, salaries, taxes.Dear customers, please submit your requests�there are plenty of files here that can be monetized.
Sources
Source
Indexed 3 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

