Ransomware victim disclosure
← All victimsThe Banyans Health and Wellness
Claimed by Qilin · listed 6 days ago
Status timeline
- ListedJun 8, 2026
- Data leakeddate unknown
At a glance
- Group
- Qilin
- Status
- Data leaked
- Country
- Australia
- Sector
- Healthcare
- Listed on leak site
- Jun 8, 2026
About the victim
AI dossier — public-source company profileThe Banyans is a private, luxury residential rehabilitation facility located in Brisbane's hinterland, Australia. It specializes in treating addiction (alcohol, drugs, gambling, gaming, sex), mental health conditions (depression, anxiety, PTSD, bipolar disorder, eating disorders), and trauma. The facility emphasizes personalized one-on-one therapy with a clinician-to-guest ratio of 14:1 and caters to high-net-worth individuals including C-suite executives.
- Industry
- Private Mental Health & Addiction Treatment
- Address
- Brisbane Hinterland, Queensland, Australia
- Employees
- 51-200
Attack summary
Severity: critical — Healthcare facility with highly sensitive patient data including mental health diagnoses, addiction treatment records, and personal medical information. HIPAA-equivalent regulated sector in Australia (Privacy Act). Patient confidentiality is core to service offering, making exposure particularly damaging.Qilin ransomware group claims to have attacked The Banyans. The specific details of the attack (encryption, exfiltration, or both) and the scope of compromised data are not disclosed in the available leak post excerpt.
Data the group says was taken
AI dossier — extracted from the leak post- Patient/guest treatment records
- Mental health diagnoses and medical history
- Addiction treatment information
- Personal identification information
- Financial/payment information
- Therapy session notes
- Staff records
What the group claims
N/A
Screenshot of the leak post

Sources
Source
Indexed 6 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

