Ransomware victim disclosure
← All victimsWynn-Reeth
Claimed by Karakurt · listed 3 years ago
Status timeline
- Listed
Apr 21, 2023
- Data leaked
At a glance
- Group
- Karakurt
- Status
- Data leaked
- Country
- United States
- Sector
- Healthcare
- Listed on leak site
- Apr 21, 2023
- Data size
- 30 GB
About the victim
AI dossier — public-source company profileWynn-Reeth is a US-based social services provider that assists individuals with daily living needs, including management of Social Security benefits. The organization appears to serve vulnerable populations requiring personal care and benefits coordination support. No public website was available to confirm additional operational details.
- Industry
- Home & Community-Based Social Services / Disability Support
Attack summary
Severity: critical — Confirmed exfiltration of regulated sensitive data at scale — SSNs, passports, and medical records belonging to a vulnerable population (disability/daily-living-support clients), totalling 30 GB, with publication imminent. This meets the critical threshold of PII at scale combined with medical and government-identity documents.Karakurt claims to have exfiltrated approximately 30 GB of data from Wynn-Reeth, asserting the trove includes both corporate information and clients' personal and medical records, including passports and Social Security numbers; the group states the data will be published imminently.
Data the group says was taken
AI dossier — extracted from the leak post- Client personally identifiable information (PII)
- Social Security numbers (SSNs)
- Passport documents
- Client medical information
- Corporate/business records
What the group claims
Wynn-Reeth provides services to the client which will help the individual meet daily living needs. They claim they can even help people manage their Social Security benefits and in the same time they helped their clients lose personal documents including passports and SSNs (and seem not to be worried much about that). We have about 30GBs of their corporate information and, as you understand, their clients personal and medical information. You will be able to check it soon by yourselves.
Sources
Source
Indexed 3 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
