Ransomware victim disclosure
← All victimsDesert Behavioral Health
listed as dbhcares.com · Claimed by Threeam · listed 1 year ago
Status timeline
- ListedMay 25, 2025
- Data leakeddate unknown
At a glance
- Group
- Threeam
- Status
- Data leaked
- Country
- United States
- Sector
- Healthcare
- Listed on leak site
- May 25, 2025
About the victim
AI dossier — public-source company profileDesert Behavioral Health (DBH) is a mental health services provider founded in 2009 in Southern Nevada, offering outpatient behavioral and psychiatric care using a bio-psycho-social integrated model. Services include individual, family, and group therapy, medication management, neurofeedback training, and telehealth options for children and adults. DBH serves thousands of clients and employs multilingual clinicians specializing in severe mental illness, PTSD, ADHD, and mood disorders.
- Industry
- Mental Health Services & Behavioral Healthcare
- Founded
- 2009
Attack summary
Severity: high — Healthcare provider with patient mental health records and PII at risk. Mental health data is highly sensitive regulated information (HIPAA-protected). Confirmed disclosure status indicates data publication, and the scale of operations (thousands of clients) suggests significant exposure.Threeam claims to have attacked Desert Behavioral Health. The leak post does not specify whether data was exfiltrated, encrypted, or both, nor does it detail what specific data or systems were compromised.
Data the group says was taken
AI dossier — extracted from the leak post- patient mental health records
- personal identifiable information
- treatment plans
- clinical assessments
- potentially insurance information
What the group claims
Desert Behavioral Health (DBH) was founded in 2009 based on the Bio-Psycho-Social integrated mental health services model. In the past years, DBH has provided outpatients mental health services for thousands of clients in Southern Nevada. Desert
Sources
Source
Indexed 1 year agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

