Ransomware victim disclosure
← All victimsTERRIO Physical Therapy & Fitness, Inc.
listed as TERRIO Therapy Fitness · Claimed by Thegentlemen · listed 5 hours ago
Status timeline
- ListedJun 20, 2026
- Data leakeddate unknown
At a glance
- Group
- Thegentlemen
- Status
- Data leaked
- Country
- Mexico
- Sector
- Consumer Services
- Listed on leak site
- Jun 20, 2026
About the victim
AI dossier — public-source company profileTERRIO is a rehabilitation and wellness provider operating multiple clinics across California's Central Valley. Founded in 1998, the company specializes in outpatient orthopedics, aquatic therapy, neuro-rehabilitation, and acute inpatient care, and has been repeatedly recognized as the Best Physical Therapy Company in Kern County.
- Industry
- Healthcare Services - Physical Therapy & Rehabilitation
- Founded
- 1998
Attack summary
Severity: high — Healthcare provider with patient data exposure; medical records and PII at scale constitute regulated sensitive data. Disclosed status is 'data_published' indicating exfiltration occurred, though specific proof count and data scope are not detailed in the excerpt.The group claims to have exfiltrated data from TERRIO. No specific attack methodology (encryption vs. data-only) is stated in the post excerpt, nor is the ransom demand disclosed.
Data the group says was taken
AI dossier — extracted from the leak post- patient records
- medical information
- personal health information
What the group claims
***.com zoominfo.com/c/terrio-therapy-fitness-inc/351115575 TERRIO Physical Therapy & Fitness is the largest rehabilitation and wellness provider in California's Central Valley, operating numerous clinics across the region.Founded in 1998, the company specializes in outpatient orthopedics, aquatic therapy, neuro-rehabilitation, and acute inpatient care.Recognized for its exceptional patient satisfaction, TERRIO has been repeatedly voted the Best Physical Therapy Company in Kern County
Sources
- Victim siteterriotherapy.com
Source
Indexed 5 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

