Ransomware victim disclosure
← All victimsFairfield Memorial Hospital
listed as fairfieldmemorial.org · Claimed by Lockbit3 · listed 2 years ago
Status timeline
- ListedJul 2, 2024
- Data leakeddate unknown
At a glance
- Group
- Lockbit3
- Status
- Data leaked
- Country
- United States
- Sector
- Healthcare
- Listed on leak site
- Jul 2, 2024
- Records
- 400 employees
About the victim
AI dossier — public-source company profileFairfield Memorial Hospital is a fully accredited, not-for-profit critical access hospital located in Southeastern Illinois (Wayne County). The hospital operates 25 acute-care beds and employs over 400 staff members, serving as a leading regional employer. It provides comprehensive healthcare services including primary care, pain management, senior life solutions, and operates multiple locations through its Horizon Healthcare network.
- Industry
- Healthcare - Critical Access Hospital
- Address
- Fairfield, Wayne County, Southeastern Illinois, United States
- Employees
- 400+
Attack summary
Severity: critical — Healthcare facility with operational disruption (encryption) and confirmed data exfiltration of patient medical records and sensitive health information. Critical access hospitals are essential infrastructure; patient PII and protected health information (PHI) at scale constitutes regulated sensitive data.LockBit3 claims to have encrypted systems at Fairfield Memorial Hospital and exfiltrated data. The group has published data as part of their disclosure, indicating both encryption and data exfiltration occurred.
Data the group says was taken
AI dossier — extracted from the leak post- Patient medical records
- Healthcare provider information
- Hospital administrative data
- Employee records
- Billing/financial information
What the group claims
Fairfield Memorial Hospital is a fully accredited, not-for-profit critical access hospital. The hospital has 25 acute-care beds and a workforce of over 400 employees. The medical staff at Fairfield Memorial Hospital is comprised of over 90 creden...
Sources
Source
Indexed 2 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

