Ransomware victim disclosure
← All victimsPrivate Company
Claimed by Snatch · listed 5 years ago
Status timeline
- ListedJan 16, 2022
- Data leakeddate unknown
At a glance
- Group
- Snatch
- Status
- Data leaked
- Country
- United States
- Sector
- Healthcare Services
- Listed on leak site
- Jan 16, 2022
About the victim
AI dossier — public-source company profileThe victim is an unidentified private U.S. healthcare company operating in the healthcare services sector. Based on the leaked file names, the organization maintains electronic medical records, patient registration data, appointment scheduling, insurance and billing information, and a patient portal. No public site or further identifying details are available.
- Industry
- Healthcare Services
Attack summary
Severity: critical — The published data includes Social Security Numbers, full patient demographics, insurance/policy details, clinical observations, medication refill requests, and patient portal accounts — constituting large-scale exfiltration of highly regulated PII and PHI under HIPAA, with data already published.The Snatch ransomware group claims to have exfiltrated a substantial set of structured database exports containing patient, provider, insurance, and portal account records from this U.S. healthcare company, and has published the data.
Data the group says was taken
AI dossier — extracted from the leak post- Social Security Numbers (SSN)
- Patient demographic records
- Patient contact information
- Emergency contact information
- Appointment information
- Provider information
- Insurance and policy information
- Guarantor/billing records
- Patient portal account credentials/data
- Caregiver records
- Medication refill requests
- Clinical observations
- Patient registration records
- Location/site data
- ETL/database export files
The group's post references roughly 39 proof files.
What the group claims
SSN_1.csv; PATIENTCONTACTS_VIEW.csv; IB_Appointment_Info.csv; location.csv; etl.csv; guarantor-2.csv; Policy_info-2.csv; contact-2.csv; contact.csv; EMED_REFILL_REQUEST.csv; ALLCAREGIVERS_VIEW.csv; IB_Provider_Info.csv; IB_Observation.csv; GHS_PatientRegistration.csv; DEMGUARANTOR-3.csv; IB_Emergency_Contact_Info.csv; etl_provider.csv; PATIENT_PORTAL_PATIENTS_VIEW.csv; etl_provider.csv; IMREPROV_CODE.csv; IB_Appointment_Info_ID.csv; IMREDEM_CODE.csv; ext_patient.csv; guarantor.csv; insurance.csv; Policy_info.csv; DEMOGRAPHICS.csv; Caregiver.csv; patient_info.csv; ARCH_DEMOGRAPHICS.csv; providers-3.csv; providers-2.csv; providers.csv; PORTAL_WEB_ACCOUNTSPORTAL_WEB_ACCOUNTS-2.csv; DEMGUARANTOR.csv; DEMGUARANTOR-2.csv; PORTAL_WEB_ACCOUNTSPORTAL_WEB_ACCOUNTS.csv; hpsite.patient.csv; Dbo.observation.info-2.csv; Dbo.observation.info.csv
Source
Indexed 5 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

