Ransomware victim disclosure
← All victimsErdem Hospital
Claimed by Direwolf · listed 16 hours ago
Status timeline
- ListedAug 30, 2026
- Data leakeddate unknown
At a glance
- Group
- Direwolf
- Status
- Data leaked
- Country
- Türkiye
- Sector
- Healthcare
- Listed on leak site
- Aug 30, 2026
About the victim
AI dossier — public-source company profileErdem Hospital is a multi-location healthcare provider operating facilities in Ümraniye, Çamlıca, and Güneşli in Turkey. The hospital provides general medical services including surgical procedures, diagnostic services, and inpatient care, with integrated digital patient management and appointment systems.
- Industry
- Healthcare - Hospital Services
Attack summary
Severity: critical — Confirmed exfiltration of 260GB including protected health information (patient medical records, identities, treatment data), personally identifiable information (employee national IDs, CVs, payroll), and regulated financial/insurance data from a healthcare provider. Scale and sensitivity of regulated healthcare data warrants critical classification.The direwolf group claims to have exfiltrated 260GB of data from Erdem Hospital's administration and ERP systems, including patient medical records, financial data, HR personnel files, and operational documentation. The group has published a detailed inventory of compromised data categories but has not disclosed specific proof files or screenshots.
Data the group says was taken
AI dossier — extracted from the leak post- Patient medical records and treatment histories
- Surgical consent forms
- Social Security Institution (SGK) invoices and healthcare transactions
- Insurance claim and reimbursement data
- Patient names and identities
- Employee CVs and employment contracts
- National ID copies
- Payroll and salary records
- Hospital financial records (budgets, expenditures, ledgers)
- Legal documentation and corporate contracts
- Occupational health and safety examination reports
- Patient complaint and rights advocacy records
What the group claims
Hospitals
The leak post
captured from the group's site```
{"article":{"id":114,"title":"Erdem Hospital","content":"\u003ch3\u003eHospital Management System – Departmental Data Inventory\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eItem\u003c/th\u003e\n\u003cth\u003eDetails\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003cstrong\u003eOrigin\u003c/strong\u003e\u003c/td\u003e\n\u003ctd\u003eHospital administration file system / ERP data modules covering medical accounting, patient services, HR, legal, and finance\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003cstrong\u003eCore Modules \u0026amp; Records\u003c/strong\u003e\u003c/td\u003e\n\u003ctd\u003e\u003cstrong\u003eMedikal Muhasebe (Medical Accounting)\u003c/strong\u003e: SGK (Social Security Institution) invoices, social security/healthcare transactions, dialysis reimbursement records, patient identity + treatment + insurance combinatorial datasets.\u003cbr\u003e\u003cbr\u003e\u003cstrong\u003eHasta Hizmetleri (Patient Services)\u003c/strong\u003e: Surgical consent forms (\u003cem\u003eAMELİYAT ONAM FORMLARI\u003c/em\u003e), patient name directory (incl. \u003cem\u0…Sources
Source
Indexed 16 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

