Ransomware victim disclosure
← All victimsUnknown Business (Owner/CFO documents)
Claimed by Rhysida · listed 4 hours ago
Status timeline
- ListedSep 18, 2026
- Data leakeddate unknown
At a glance
- Group
- Rhysida
- Status
- Data leaked
- Listed on leak site
- Sep 18, 2026
- Data size
- 132 GB
- Records
- 54,339 files
About the victim
AI dossier — public-source company profileThe leak post conflates multiple victim organizations across different sectors (electronics, medical/clinical, legal services, pharmaceutical, healthcare). No single coherent company profile can be constructed from the data advertised.
Attack summary
Severity: critical — Post advertises confirmed exfiltration of highly regulated data at massive scale: PHI under HIPAA (methadone clinic under 42 CFR Part 2 — strictest US regime), SSNs and background checks at scale (721 dossiers plus thousands more), pharmaceutical controlled-substance records, medical records across multiple healthcare entities, bank account credentials, and confidential legal discovery. Multiple regulated sectors and jurisdictions affected.Rhysida claims exfiltration of data from multiple unrelated entities spanning 814,500 to 3.5M files. Alleged data includes background checks with SSNs, medical records (methadone clinic, surgical pathology, cancer center, neonatal), corporate financials, bank details, payroll, litigation files, and pharmaceutical narcotics records across US and Philippine jurisdictions.
Data the group says was taken
AI dossier — extracted from the leak post- Background checks with SSNs in filenames
- Medical records (methadone clinic, surgical, neonatal)
- Patient PHI (PhilHealth IDs, cancer markers, admission records)
- Corporate bank account details and ACH/EFT forms
- Payroll and HR records with SSNs, home addresses, DOB
- Legal litigation files and client confidential correspondence
- Pharmaceutical narcotics/controlled-substance records
- Executive and CFO personal tax returns and credit applications
- Employee evaluations, salary, bonuses
- Medical insurance and drug-test records
- Accredited physician registers and PRC licenses
- Financial statements and audit records
What the group claims
A company whose leaked data includes owner and CFO personal documents, corporate financials, employee evaluations, medical records, and drug tests.
The leak post
captured from the group's siteAxdia International is a German electronics company that brings together a wide range of modern small electronics and electric mobility products. With just 7 days on the clock, seize the opportunity to bid on exclusive, unique, and impressive data. Open your wallets and be ready to buy exclusive data. We sell only to one hand, no reselling, you will be the only owner! 814,500 files, 2.6 TB721 background-check dossiers with full SSNs in filenames, including 2026 records.Tens of thousands of medical faxes, 2022 to 2026, with patient names and diagnoses.Methadone clinic records under 42 CFR Part 2, the strictest US confidentiality regime.47,602 medical-assistance files with driver licenses, Green Cards, SSN cards, tax forms and bank data.County payroll registers with all salaries, HR memos, contracts, pension and discipline databases.Jail gang-intelligence files with a gang-member master list. With just 7 days on the clock, seize the opportunity to bid on exclusive, unique, and impressive data. Open your wallets and be ready to buy exclusive data. We sell only to one hand, no reselling, you will be the only owner! Total files 338,542Total size 710.6 GBFull corporate bank account detai…
Data the group says was taken
- employee evaluations
- salary rates
- bonuses
- job offers
- family documents
- client credit reports
- bankruptcy records
- tax documents
- medical records
- corporate financials
- personal tax returns
- credit applications
- signed checks
- corporate credit cards
- drug tests
- health insurance records
Screenshot of the leak post

Sources
Source
Indexed 4 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

