Ransomware victim disclosure
← All victimsFMRS Health Systems
Claimed by Qilin · listed 3 months ago
Status timeline
- ListedMar 13, 2026
- Data leakeddate unknown
At a glance
- Group
- Qilin
- Status
- Data leaked
- Country
- United States
- Sector
- Healthcare
- Listed on leak site
- Mar 13, 2026
About the victim
AI dossier — public-source company profileFMRS Health Systems, Inc. is a nonprofit community behavioral health center headquartered in Raleigh County, West Virginia, originally founded in 1969 as FMRS Mental Health Council. It provides adult and children's behavioral health, crisis services, intellectual and developmental disability (IDD) services, primary care, and substance use treatment across four West Virginia counties. The organization operates multiple offices and transportation services serving residents of Fayette, Monroe, Raleigh, and Summers Counties.
- Industry
- Behavioral Health & Community Mental Health Services
- Address
- Raleigh County, West Virginia (serves Fayette, Monroe, Raleigh & Summers Counties, WV); phone 304-256-7100
- Founded
- 1969
Attack summary
Severity: critical — FMRS is a healthcare provider handling highly sensitive regulated data including mental/behavioral health, substance use treatment, and IDD records — all protected under HIPAA. Data has been confirmed published by the threat actor, and the victim's own website acknowledges a data security incident, indicating exfiltration of sensitive medical PII at scale.Qilin claims to have compromised FMRS Health Systems with data published ('data_published' status); the organization's own website displays a 'Notice of Data Security Incident,' corroborating an intrusion. The specific volume or categories of exfiltrated data are not enumerated in the leak post, but the healthcare context and published-data status indicate exfiltration of patient and/or operational records.
Data the group says was taken
AI dossier — extracted from the leak post- Patient health records
- Behavioral health treatment data
- Substance use treatment records
- IDD services records
- Personal identifying information (PII)
- Crisis services records
- Employee/HR data
What the group claims
N/A
The leak post
captured from the group's siteQilin blog Sorting Created At Name Bluize Software Company url Zoom Info May 13, 2026 0 photos Learn More Mayer Law Firms & Legal Services Company url Zoom Info May 13, 2026 0 photos Learn More Spirit Medical Transport Ambulance Services Company url Zoom Info May 13, 2026 0 photos Learn More Domaine Des Tournels Manufacturing Company url May 13, 2026 0 photos Learn More Johnson Carter Architects Architecture, Engineering & Design Company url Zoom Info May 13, 2026 0 photos Learn More LTJ Industrial Services Industrial Machinery & Equipment Company url Zoom Info May 13, 2026 0 photos Learn More Brand X Hydrovac Services Civil Engineering Construction Company url Zoom Info May 13, 2026 0 photos Learn More John G Yphantides A Professional Law Law Firms & Legal Services Company url Zoom Info May 13, 2026 0 photos Learn More One Legal Law Firms & Legal Services Company url Zoom Info May 13, 2026 0 photos Learn More The Gravity Group Architecture, Engineering & Design Company url Zoom Info May 12, 2026 3 photos Learn More Mediapost Spain Advertising & Marketing Company url Zoom Info May 12, 2026 13 photos Learn More + 6 more AppDirect Software Company url Zoom Info May 11, 2026 0 photos …
Sources
Source
Indexed 3 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

