Ransomware victim disclosure
← All victimsColorado Health Network Inc
Claimed by cephalus · listed 9 months ago
Status timeline
- Listed
Aug 28, 2025
- Data leaked
At a glance
- Group
- cephalus
- Status
- Data leaked
- Country
- United States
- Sector
- Healthcare
- Listed on leak site
- Aug 28, 2025
About the victim
AI dossier — public-source company profileColorado Health Network (CHN), founded in 1983, is Colorado's oldest and largest provider of services and programs for people living with or impacted by HIV. The organization offers integrative medical, oral health, behavioral health, prevention, and social support services across multiple locations throughout Colorado including Denver, Fort Collins, Greeley, Colorado Springs, Pueblo, and Grand Junction. CHN serves clients regardless of ability to pay and operates both in-person and via telehealth.
- Industry
- HIV & Sexual Health Services / Community Health
- Address
- 6260 East Colfax Ave, Denver, CO 80220
- Founded
- 1983
Attack summary
Severity: critical — Colorado Health Network serves a highly vulnerable population of HIV-positive individuals and those with STIs. A 900 GB exfiltration from a healthcare nonprofit of this nature almost certainly includes regulated medical data (HIPAA-protected PHI), HIV status, behavioral health records, and PII at scale — all categories of maximally sensitive information. Exposure of HIV status in particular carries severe stigma and legal implications.The ransomware group Cephalus claims to have exfiltrated over 900 GB of data from Colorado Health Network and has indicated the data will be published imminently. The disclosure status is marked as data_published, suggesting exfiltration of sensitive organizational data is confirmed or in progress.
Data the group says was taken
AI dossier — extracted from the leak post- Patient medical records
- HIV/STI health status information
- Behavioral health records
- Dental health records
- Personal identifying information (PII)
- Financial assistance records
- Housing and social support case files
- Medication access records
- Insurance information
- Staff/personnel data
What the group claims
900G+ data coming soon
Sources
- Victim sitecoloradohealthnetwork.org
Source
Indexed 9 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
