Ransomware victim disclosure
← All victimsRainier Clinical Research Center
Claimed by INC Ransom · listed 4 months ago
Status timeline
- ListedFeb 23, 2026
- Data leakeddate unknown
At a glance
- Group
- INC Ransom
- Status
- Data leaked
- Country
- United States
- Sector
- Healthcare
- Listed on leak site
- Feb 23, 2026
About the victim
AI dossier — public-source company profileRainier Clinical Research Center is a clinical research facility based in the United States specializing in clinical trials for diabetes, medical devices, and high-volume studies. The center operates a purpose-built 15,000 square-foot research space and has completed over 700 studies across approximately 30 years of operation.
- Industry
- Clinical Research & Trials
Attack summary
Severity: critical — The victim is a clinical research center handling sensitive medical and patient data from hundreds of studies, including regulated health information (PHI/PII) on trial participants. The disclosed status is 'data_published' and full data release is threatened, representing confirmed exfiltration of regulated medical data at scale.INC Ransom claims to have compromised Rainier Clinical Research Center and has published the disclosure with a stated intent to release all exfiltrated data the following week; the post implies data exfiltration is pending full publication.
Data the group says was taken
AI dossier — extracted from the leak post- Clinical trial data
- Patient health records
- Medical device study records
- Diabetes research data
- Research participant PII
What the group claims
Rainier Clinical Research Center is a leading research facility specializing in clinical trials for diabetes, medical devices, and high-volume studies, with over 700 studies completed in 30 years. The center provides a purpose-built 15,000 square-foot research space We will publish all the information next week.
Source
Indexed 4 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

