Ransomware victim disclosure
← All victimsJefferson County Hospital
listed as Jefferson County Health Center · Claimed by Karakurt · listed 3 years ago
Status timeline
- Listed
Jul 3, 2023
- Data leaked
At a glance
- Group
- Karakurt
- Status
- Data leaked
- Country
- United States
- Sector
- Healthcare
- Listed on leak site
- Jul 3, 2023
- Data size
- 1.1 TB
About the victim
AI dossier — public-source company profileJefferson County Hospital is a 25-bed critical access facility located in Waurika, Oklahoma, serving residents of Jefferson County and surrounding communities. As a critical access hospital, it provides essential inpatient and outpatient medical services to a rural population. The facility handles medical records, diagnostic testing, and administrative/financial operations.
- Industry
- Critical Access Hospital / Rural Healthcare
- Address
- Waurika, Oklahoma, United States
Attack summary
Severity: critical — Confirmed exfiltration of 1.1 TB of regulated healthcare data including patient medical records and PII at scale from a hospital, constituting a likely HIPAA-covered breach of sensitive medical and financial information affecting patients and employees.Karakurt claims to have exfiltrated approximately 1.1 TB of data from Jefferson County Hospital, including patient medical records, test results, employee and patient personal information, and accounting and financial records, with publication of the data announced for an upcoming summer release.
Data the group says was taken
AI dossier — extracted from the leak post- Patient medical records
- Diagnostic test results
- Patient personal information (PII)
- Employee personal information (PII)
- Accounting records
- Financial information
What the group claims
Jefferson County Hospital, Waurika, Oklahoma, is a 25-bed critical access facility providing medical services to residents of Jefferson County and surrounding communities. 1.1 TB from the medical facility: medical records, test results, and personal information of employees and patients. Accounting and financial information is abundant. This data will be uploaded during upcoming summer release.
Sources
Source
Indexed 3 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
