Ransomware victim disclosure
← All victimsUnknown US Healthcare/County Entity
Claimed by Rhysida · listed 1 day ago
Status timeline
- ListedOct 1, 2026
Current state: Listed for ransom
At a glance
- Group
- Rhysida
- Status
- Listed for ransom
- Country
- United States
- Sector
- Healthcare / Government
- Listed on leak site
- Oct 1, 2026
- Data size
- 2.6 TB
- Records
- 814,500 files; 721 background-check dossiers; 47,602 medical-assistance files
About the victim
AI dossier — public-source company profileUnknown US healthcare or county entity. The victim name provided offers no identifying details; the leak post contains multiple unrelated victim disclosures (a German marketing agency, a Florida law firm, Italian professional firms, and HOA/banking data aggregators) but no coherent single victim matching the stated sector.
Attack summary
Severity: critical — Confirmed exfiltration of regulated sensitive data at scale: PII (SSNs, financial account credentials) for thousands of individuals; medical records; criminal case files and law enforcement discovery involving minors; tax and banking secrets; and private firm credentials and signing keys. Data includes identifiable victims under active legal proceedings and ICE custody.Rhysida claims to have exfiltrated 2.6 TB of data. The post lists multiple distinct breaches: a criminal defense law practice with ~175+ client case files including sensitive criminal charges and discovery; hundreds of US HOAs and thousands of homeowners' financial records including SSNs, bank account numbers, and tax documents; and Italian accounting and legal firm networks with client tax filings, credentials, and bank statements.
Data the group says was taken
AI dossier — extracted from the leak post- Criminal case files (~175+ clients)
- Police bodycam video (~206 GB)
- 911 recordings and jail calls
- Victim and witness data
- Homeowners' SSNs and bank account numbers
- W-9 forms and IRS 1099 filings
- ACH debit files and brokerage statements
- HOA assessments and bankruptcy records
- HUD-1 settlement documents
- SQL Server databases (RM_Warehouse, RM_Sales, CiraBooks_GL)
- Italian law firm case files (civil, criminal, bankruptcy)
- Italian accounting client tax filings (730, CU, F24)
- SOGEI tax-signing keys
- Bank statements and credentials
- Medical documents (GDPR Art. 9)
What the group claims
US entity with background-check dossiers, medical faxes including patient diagnoses, methadone clinic records under 42 CFR Part 2, medical-assistance files with driver licenses and SSNs, county payroll registers, HR records, and jail records.
The leak post
captured from the group's siteWith more than 40 employees, the agency manages national and international online projects of companies from a wide range of industries. Based in Berlin, Dresden, Munich and Cologne, has been a specialist in online marketing for more than twelve years. With just 7 days on the clock, seize the opportunity to bid on exclusive, unique, and impressive data. Open your wallets and be ready to buy exclusive data. We sell only to one hand, no reselling, you will be the only owner! [Law Offices of R. David Williams, P.A.](https://www.dwilliamslaw.com) Contents. A complete dossier of the firm's criminal defense practice covering ~175+ clients: felonies (an undercover sex sting involving a minor - Ramirez; domestic violence robbery - Valderrama, involving a 4-year-old child; felony DUI - Segula; fraud - B. Williams), a core caseload of ~10 DUI matters (including an arrest at breath readings of 0.011 and SCRAM alcohol monitoring), violations of probation (VOP), FDLE expungement packets with FD-258 fingerprint cards, a 'red flag' Risk Protection Order (RPO), 2 clients in ICE custody, and a material witness under GPS monitoring for 3+ years. Attorney fees range from $750 to $25,000. The case fil…
Data the group says was taken
- background-check dossiers
- SSNs
- medical faxes
- patient diagnoses
- methadone clinic records
- medical-assistance files
- driver licenses
- Green Cards
- SSN cards
- tax forms
- bank data
- payroll registers
- HR records
- pension records
- discipline records
- jail records
Screenshot of the leak post

Sources
Source
Indexed 1 day agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

