Ransomware victim disclosure
← All victimsPhysical & Occupational Therapy Examiners of Texas
Claimed by Hunters · listed 2 years ago
Status timeline
- ListedJul 25, 2024
- Data leakeddate unknown
At a glance
- Group
- Hunters
- Status
- Data leaked
- Country
- United States
- Sector
- Healthcare
- Listed on leak site
- Jul 25, 2024
About the victim
AI dossier — public-source company profileThe Executive Council of Physical Therapy and Occupational Therapy Examiners (ECPTOTE) is a State of Texas agency responsible for licensing and regulating physical therapy and occupational therapy practitioners in Texas. It maintains professional standards and protects public health through credential verification and disciplinary oversight.
- Industry
- Healthcare – Professional Licensing & Regulation
Attack summary
Severity: high — Government regulatory agency with confirmed dual compromise (encryption + exfiltration). Database likely contains PII of thousands of licensed professionals and applicants, plus sensitive disciplinary and background check records. Operational disruption evident (system transition mentioned as recent). No proof files quantified, but the nature of the victim and dual attack vector elevates risk.The hunters group claims to have both encrypted systems and exfiltrated data from ECPTOTE. The specific data exfiltrated has not been detailed in the available leak post.
Data the group says was taken
AI dossier — extracted from the leak post- Licensee personal records
- Application data
- License status information
- Practitioner contact information
- Disciplinary records
- Criminal history evaluations
What the group claims
Country : United States of America - Exfiltraded data : yes - Encrypted data : yes
Sources
Source
Indexed 2 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

