Ransomware victim disclosure
← All victimsDrChrono
Claimed by coinbasecartel · listed 4 hours ago
Status timeline
- Listed
Jun 7, 2026
Current state: Listed for ransom
At a glance
- Group
- coinbasecartel
- Status
- Listed for ransom
- Sector
- Healthcare IT
- Listed on leak site
- Jun 7, 2026
- Data size
- 43 GB
About the victim
AI dossier — public-source company profileDrChrono is a healthcare IT company that provides cloud-based practice management and electronic health record (EHR) software solutions for medical practices. The company serves healthcare providers with digital tools for patient management and billing.
- Industry
- Healthcare IT / Medical Practice Management Software
Attack summary
Severity: critical — Healthcare IT breach with 43 GB of exfiltrated data affecting a medical practice management platform serving multiple healthcare providers. Potential exposure of patient PII, medical records, and HIPAA-regulated information at scale. Confirmed exfiltration by threat actor.The coinbasecartel group claims to have breached DrChrono's systems and exfiltrated approximately 43 GB of data. The attackers state they had unauthorized access to internal systems and that the victim declined to pay the ransom demand.
Data the group says was taken
AI dossier — extracted from the leak post- Patient records
- Practice management data
- Electronic health records
- System files
The leak post
captured from the group's siteWe are moving to a new storage solution, all leaks will be made available sooin.A New panasonic.aero DrChrono demand.io Our SimpleX chat ID has changed. Please add us on https://smp5.simplex.im/a#bAEa5tPvMugwBWZdcOYnj_gBicRCy3HLz2A7oC6KjF0 They had no idea they were breached, we were roaming freely in their systems, they don't want to pay and that's fine, pay your employees more or we will just keep doing this to you. Samples will be uploaded soon. — We are looking for new partners/insiders. Send us a message to dicuss Peru LNG (Hunt LNG Operating Company) Rogiken / institute of Science Tokyo Lacoste - Updated with proof Canada Goose - Updated with proof Flash Charm INC - (IDERA) Verimatrix - 43gb Leaked PC SOFT FRANCE - Leaked JBS Brazil - Sample uploaded Dolby Laboratories - updated Sample RAKS Sp. z o.o. b Leaked ILLUMINA - Data uploaded ATG - New samples added Propertyfinder / PropSpace CRM - In aucitioin place your bids now !!! We are moving to a new storage solution, all leaks will be made available sooin.A New panasonic.aero DrChrono demand.io Our SimpleX chat ID has changed. Please add us on https://smp5.simplex.im/a#bAEa5tPvMugwBWZdcOYnj_gBicRCy3HLz2A7oC6KjF0 They had no i…
Screenshot of the leak post

Sources
Source
Indexed 4 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.
