Ransomware victim disclosure
← All victimsStellar Nursing Homes (operating as Salter HealthCare)
listed as Salter HealthCare · Claimed by qilin · listed 3 days ago
Status timeline
- Listed
May 17, 2026
- Data leaked
At a glance
- Group
- qilin
- Status
- Data leaked
- Country
- GB
- Sector
- Healthcare
- Listed on leak site
- May 17, 2026
About the victim
AI dossier — public-source company profileSalter HealthCare operates under the Stellar Nursing Homes brand and runs multiple post-acute, rehabilitation, and skilled nursing centers in Massachusetts, including locations in Aberjona, Winchester, and Woburn. The organization provides short-term rehabilitation, long-term care, respite care, and hospice care services to local communities. Despite the victim country being listed as GB, the public website indicates all facilities are located in Massachusetts, USA.
- Industry
- Post-Acute & Skilled Nursing Facility Care
- Address
- 781 Main Street area, Winchester, MA (multiple locations in Aberjona, Berlin, Birchwood Terrace, Burlington, Harrington House, Winchester, Woburn, Massachusetts, USA)
Attack summary
Severity: critical — The victim is a multi-site skilled nursing and rehabilitation healthcare provider handling sensitive patient PII and medical records; data has been published by the threat actor, indicating confirmed exfiltration of regulated health data (likely HIPAA-covered), which meets the critical threshold.The Qilin ransomware group claims to have attacked Salter HealthCare and has published data ('data_published' status), though the leak post itself contains no textual detail on specific methods or data volumes exfiltrated.
Data the group says was taken
AI dossier — extracted from the leak post- Patient health records (likely, given healthcare sector)
- Resident personal information
- Staff/employee records
- Financial/billing data (online payment systems referenced)
- Operational facility data
What the group claims
N/A
The leak post
captured from the group's siteThe requested page does not exist. The above error occurred while the Web server was processing your request. Please contact us if you think this is a server error. Thank you.
Sources
Source
Indexed 3 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
