Ransomware victim disclosure
← All victimsUnknown Clinic
Claimed by Rhysida · listed 2 days ago
Status timeline
- ListedAug 29, 2026
Current state: Listed for ransom
At a glance
- Group
- Rhysida
- Status
- Listed for ransom
- Sector
- Healthcare
- Listed on leak site
- Aug 29, 2026
- Data size
- 5.79 TB
- Records
- 160,870 patients, 4.18 million diagnoses, 7.6 million EHR scans
About the victim
AI dossier — public-source company profileAn unknown clinic operating in a German-speaking jurisdiction (references to Berlin administrative court, German government agencies, and German-language file names). The organization maintains patient records, financial systems, and appears to have government contracts or oversight relationships based on references to state security and classified-material handling protocols.
- Industry
- Healthcare
Attack summary
Severity: critical — Confirmed exfiltration at massive scale of highly regulated healthcare data (160,870+ patients, millions of diagnostic records, unencrypted EHRs) constituting GDPR-regulated PII; additionally, exposure of classified German government materials (Bundesrat protocols, state security files, KRITIS infrastructure vulnerability data, declassified documents) representing a national security breach.Rhysida claims to have exfiltrated 5.79 TB of data including 9.06 million files spanning patient records, financial data, personnel files, and sensitive government materials. The group advertises approximately 3.28 TB of structured medical data including 160,870 patient records, 4.18 million diagnoses, and 7.6 million unencrypted EHR scans, along with encrypted credentials, state secrets, and classified government protocols.
Data the group says was taken
AI dossier — extracted from the leak post- 160,870 patient records
- 4.18 million diagnoses
- 7.6 million unencrypted EHR scans
- SSNs and passport scans
- 16,389 emails
- 11,963 phone numbers
- 148 IBANs
- Plaintext credentials
- Financial statements and payroll records
- Personnel files (>5,000 records)
- Disciplinary/legal proceedings files
- Bundesrat committee protocols
- Classified-material handling data
- Berlin water supply vulnerability analyses
- 3,226 NDA documents
- CRM system backup
- M&A deal materials (70,000+ files from data rooms)
The group's post references roughly ~1.44 million files scanned and categorized proof files.
What the group claims
Large SQL databases containing the clinic's entire lifetime of information, including patient records, diagnoses, EHR scans, and personal data.
The leak post
captured from the group's site9,056,196 files3.28 TBLarge SQL databases containing the clinic's entire lifetime of information.Major databases:160,870 patients4.18 million diagnoses7.6 million unencrypted EHR scansSSN, passports, and other personal data.Financial statements, salaries, taxes.Dear customers, please submit your requests�there are plenty of files here that can be monetized. With just 7 days on the clock, seize the opportunity to bid on exclusive, unique, and impressive data. Open your wallets and be ready to buy exclusive data. We sell only to one hand, no reselling, you will be the only owner! Total capacity 5.79 TBArchive scale: ~1.44 million files scanned; by category � Maps/Geo 124,823, Legal/complaints 77,939, Financial 55,553, Contracts 46,522, HR 27,299,Government supervisory 13,142, Confidential 11,777, Infrastructure 8,110, Passwords 5,941, Health 2,738, Contacts 2,287.PII leak: 16,389 e-mails, 11,963 phone numbers, 12,076 individuals, 148 IBANs.Credentials in plaintext: Geb�udeAtlas, the ePayment PAYONE payment database, personal 'password safes' (danz, kramell � Z_ADMIN database accounts, franssen), leadership credentials.Disciplinary proceedings: the ANDERSON case (432 files, 2025�2026,…
Data the group says was taken
- SQL databases
- EHR scans
- SSN
- passports
- personal data
- financial statements
- salaries
- taxes
Screenshot of the leak post

Sources
Source
Indexed 2 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

