Ransomware victim disclosure
← All victimsUnknown German/European Organization
Claimed by Rhysida · listed 2 hours ago
Status timeline
- ListedAug 28, 2026
Current state: Listed for ransom
At a glance
- Group
- Rhysida
- Status
- Listed for ransom
- Listed on leak site
- Aug 28, 2026
- Data size
- 5.79 TB
- Records
- 16,389 unique email addresses, 11,963 phone numbers, 12,076 individuals, 148 IBANs
About the victim
AI dossier — public-source company profileThe leak post is a composite of multiple victims, not a single organization. It lists SIA Medical (Melbourne dental/medical clinics), CRI Electric (San Antonio electrical services), an unnamed German/European organization with government/infrastructure data, an unnamed healthcare provider with 160k+ patient records, and Fairview Dental Group. No coherent single company can be identified.
Attack summary
Severity: critical — Multiple confirmed exfiltrations of highly regulated healthcare data (160k+ patient medical records with diagnoses, SSNs, HIV and psychiatric records), government/infrastructure files marked classified/KRITIS, financial and identity documents at scale, and plaintext system credentials. Exposure of sensitive personal data categories (health, government secrets, disability status) under GDPR Article 9.Rhysida claims exfiltration of data from multiple unrelated organizations totaling 5.79 TB. Claimed data includes patient medical records, employee identity documents, financial records, government contracts, and system credentials. The post itself does not state a ransom demand figure.
Data the group says was taken
AI dossier — extracted from the leak post- patient medical records (20k+ records)
- patient X-rays and imaging
- names, dates of birth, Medicare numbers
- clinical notes and dossiersStaff identity documents
- passports, driver's licenses
- police checks
- plaintext credentials
- HR records and employment contracts
- staff incident reports
- legal and financial documents
- bank details
- federal account artifacts
- W-9 forms with SSN/EIN
- payroll records
- government contract bids
- CRM system backups
- share purchase agreements
- NDAs
- annual reports
- KYC/AML files
- passports and ID scans
- email archives
- SQL backups
What the group claims
Large organization with legal, financial, HR, oversight, and infrastructure data. References to House of Representatives (GWTV), ProFISKAL, and KRITIS suggest a German public or semi-public entity.
The leak post
captured from the group's siteSIA Medical was established in 1993 and was founded by Dr Martin Sia in Melbourne's northwest. 9 clinics - Box Hill, Burwood, Croydon, Essendon, Footscray, Moonee Ponds, Montrose, Mulgrave and Berwick.**We are pleased to present:** ~20,000 patient medical records - names, dates of birth, Medicare numbers, clinical notes, insurance and work-cover files, full patient dossiersStaff identity documents - passports, driver's licenses, police checks, tax file declarations of doctors and employeesPlaintext credentials - logins and passwords for clinical systems (Synapse imaging, PRODA, terminal server, doctor accounts)HR records - signed employment contracts, staff incident reports, immunisation registersLegal & financial - subpoenas, complaints, Bupa contracts, bank details (BSB/ABN), provider payment forms With just 7 days on the clock, seize the opportunity to bid on exclusive, unique, and impressive data. Open your wallets and be ready to buy exclusive data. We sell only to one hand, no reselling, you will be the only owner! CRI Electric is a veteran-owned business based in San Antonio, providing professional electrical services since 1998. They cater to both residential and commercial…
Data the group says was taken
- legal documents
- complaints
- OWi proceedings
- lawsuits
- legal opinions
- financial documents
- budgets
- invoices
- contracts
- NDAs
- procurement
- HR records
- personnel files
- payroll
- performance reviews
- government oversight documents
- confidential/secret files
- infrastructure/KRITIS data
- risk analysis
- emergency plans
- passwords/credentials
- health/insurance records
- contact/address databases
- email addresses
- phone numbers
- IBANs
Screenshot of the leak post

Sources
Source
Indexed 2 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

