Ransomware victim disclosure
← All victimsMercy Hospital & Medical Center Chicago
listed as Insight Hospital & Medical Center Chicago · Claimed by Termite · listed 3 months ago
Status timeline
- Listed
Feb 24, 2026
- Data leaked
At a glance
- Group
- Termite
- Status
- Data leaked
- Country
- United States
- Sector
- Healthcare
- Listed on leak site
- Feb 24, 2026
About the victim
AI dossier — public-source company profileMercy Hospital & Medical Center, founded in 1852, is a member of Trinity Health and operates as a teaching hospital headquartered in Chicago, Illinois. It is one of the oldest hospitals in Chicago, providing a broad range of inpatient and outpatient medical services to the South Side Chicago community. The facility listed at insightchicago.com appears to be operating under the Insight Hospital & Medical Center brand at the same location following Mercy Hospital's closure/transition.
- Industry
- Acute Care Hospital & Medical Services
- Address
- 2525 S. Michigan Avenue, Chicago, Illinois 60616
- Employees
- 1001-5000
- Founded
- 1852
Attack summary
Severity: critical — Confirmed data publication by a ransomware group targeting a hospital; healthcare environments inherently involve regulated patient data (HIPAA-protected PHI/PII at scale), making any confirmed exfiltration and publication a critical severity event.The Termite ransomware group claims to have attacked the hospital and published data, asserting exfiltration of organizational data; the leak post describes the institution as a Trinity Health teaching hospital founded in 1852. The disclosure status is listed as data_published, indicating data has been released.
Data the group says was taken
AI dossier — extracted from the leak post- Patient health records
- Personal identifiable information (PII)
- Employee records
- Financial records
- Hospital administrative documents
What the group claims
Founded in 1852 Mercy Hospital & Medical Center is a member of Trinity Health. They are a teaching hospital headquartered out of Chicago, Illinois
Sources
Source
Indexed 3 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
