Ransomware victim disclosure
← All victimsAffinia Healthcare
Claimed by Termite · listed 2 days ago
Status timeline
- ListedJul 28, 2026
- Data leakeddate unknown
At a glance
- Group
- Termite
- Status
- Data leaked
- Country
- United States
- Sector
- Healthcare
- Listed on leak site
- Jul 28, 2026
About the victim
AI dossier — public-source company profileAffinia Healthcare is a community health organization operating six clinics across the St. Louis area, providing comprehensive medical services including primary care, dental, behavioral health, OB/GYN, pediatrics, and specialized programs. The organization serves all family members with particular focus on underprivileged and underserved communities.
- Industry
- Community Health Centers & Primary Care
- Address
- St. Louis, Missouri, US (multiple locations: Biddle, North Florissant, Ferguson, Lemp, South Broadway, Page Avenue)
Attack summary
Severity: high — Healthcare provider with confirmed data publication and patient-facing operations across multiple clinics. Likely exposure of Protected Health Information (PHI) and personally identifiable information at scale affecting patients across six locations, though specific proof count and data categories are not detailed in the provided excerpts.The termite group claims to have attacked Affinia Healthcare and published data. No specific details on encryption status, data exfiltration scope, or threatened data types are provided in the leak post excerpt.
Data the group says was taken
AI dossier — extracted from the leak post- Patient medical records
- Personal health information
- Patient contact information
- Clinical notes
What the group claims
Affinia Healthcare is dedicated to providing high-quality medical care and exceptional services across multiple locations in the St. Louis area. They offer a comprehensive range of health services including primary care, dental, behavioral health, and specialized programs for all family members, particularly focusing on underprivileged communities.
Sources
Source
Indexed 2 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

