Ransomware victim disclosure
← All victimsProMantra
Claimed by METAENCRYPTER · listed 3 hours ago
Status timeline
- ListedSep 18, 2026
Current state: Listed for ransom
At a glance
- Group
- METAENCRYPTER
- Status
- Listed for ransom
- Country
- United States
- Sector
- Healthcare Technology
- Listed on leak site
- Sep 18, 2026
- Data size
- 1 TB
About the victim
AI dossier — public-source company profileProMantra is a U.S.-based healthcare technology and business process services company founded in 2003. It specializes in Revenue Cycle Management (RCM), medical billing, healthcare data processing, and automation, providing technology-enabled services to help healthcare providers manage financial and administrative processes associated with patient care.
- Industry
- Healthcare Technology & Revenue Cycle Management
- Founded
- 2003
Attack summary
Severity: critical — ProMantra operates in healthcare technology with focus on medical billing and healthcare data processing, indicating probable access to Protected Health Information (PHI) and Personally Identifiable Information (PII) at scale. Confirmed exfiltration of ~2 TB of internal data from a healthcare company handling patient financial and administrative records meets the threshold for critical severity due to regulated healthcare data exposure.METAENCRYPTER claims to have exfiltrated approximately 2 TB of internal data from ProMantra over the course of the attack. The group states the company remains vulnerable and has continued to exfiltrate additional data. The leak post describes a staged extortion approach involving partial disclosure of samples, full public release if demands are not met, and notification to regulatory authorities.
Data the group says was taken
AI dossier — extracted from the leak post- Internal company files and systems
- Healthcare data processing records
- Business process documentation
- Revenue Cycle Management systems data
What the group claims
A U.S.-based healthcare technology and business process services company specializing in Revenue Cycle Management (RCM), medical billing, healthcare data processing, and automation. Founded in 2003.
The leak post
captured from the group's siteThis platform publishes data belonging to organizations that have elected to forgo negotiation entirely.Upon a company's initial listing, the complete manifest of exfiltrated files is disclosed alongside a curated selection of representative samples. Should the organization fail to establish contact prior to the stated deadline, a portion of the compromised data is released into the public domain.Should all subsequent attempts at resolution prove fruitless, the full volume of acquired data is made permanently and unconditionally available to the general public — accessible without restriction to journalists, researchers, competitors, and any other interested party. Simultaneously, formal notifications are dispatched to the relevant data protection and regulatory authorities: the and in the United States; the , , , and the across Europe; the (Singapore), (South Korea), and (Japan) throughout Asia — all of whom are mandated to investigate and impose penalties upon the affected organization.In the event that a mutual agreement is reached, every file in our possession is permanently and irrevocably destroyed, and all references to that organization are expunged from this platform in th…
Screenshot of the leak post

Sources
Source
Indexed 3 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

