Ransomware victim disclosure
← All victimsHealth Management Systems
Claimed by Dragonforce · listed 3 months ago
Status timeline
- ListedMar 19, 2026
- Data leakeddate unknown
At a glance
- Group
- Dragonforce
- Status
- Data leaked
- Country
- United States
- Sector
- Healthcare
- Listed on leak site
- Mar 19, 2026
About the victim
AI dossier — public-source company profileHealth Management Systems (hms.com.au) is an Australian software company that provides business management and care coordination software for Support at Home package providers and NDIS-related services. Their products include scheduling automation, mobile notification systems, staff management tools, and transit/listener solutions designed to help care providers stay compliant and improve client outcomes. The company operates primarily in the Australian aged care and disability support sector.
- Industry
- Healthcare Software & Practice Management
Attack summary
Severity: critical — The company handles sensitive healthcare and disability support data (NDIS clients, care plans, staff and client PII) in a regulated sector; data_published status indicates confirmed exfiltration and release of potentially regulated health and personal information at scale.Dragonforce claims to have exfiltrated data from Health Management Systems, with the disclosure status recorded as data_published, indicating stolen data has been released or made available. No specific ransom amount or data size was stated in the post.
Data the group says was taken
AI dossier — extracted from the leak post- Client care records
- Staff management data
- Business operations documents
- NDIS-related client information
- Scheduling and operational data
What the group claims
Health Management Systems provides tailored health care software designed to enhance business processes and improve staff management for service providers in community health, aged care, and related sectors. Their solutions are NDIS ready and focus on automating scheduling, tracking budgets, and improving client care through efficient practice management. The software aims to maximize staff productivity, reduce client wait times, and ensure compliance with various funding portals. Their target clients include organizations supporting clients with government-funded schemes and packages, ensuring better care delivery
The leak post
captured from the group's site```
{"data":{"count":483,"publications":[{"uuid":"b008b8b7-0e47-416f-adcd-2313d8136de4","created_at":"2026-05-08T20:56:13.122134Z","name":"CF Evans Construction","website":"www.cfevans.com","address":"125 Regional Pkwy Ste 200, Orangeburg, South Carolina, 29118, United States","description":"A recognized leader in the multi-family housing construction industry, CF Evans Construction provides a product for developers. The company has thrived amid six decades.\nThe data of this company includes:\n Corporate correspondence of senior executives\n Financial documents\n HR documents\n Accounting documents\n Certificates, contracts, passwords, databases, and much more.","weight":4775795351552,"is_timer_publication_stopped":false,"timer_publication":"2026-05-22T07:48:00Z","try_again":false,"tags":[],"logo_uuid":"f4e582dd-6562-4590-bac8-2b9e5c564853","is_transfering":false},{"uuid":"3827192f-9bb3-490c-9c1c-d28b382510cd","created_at":"2026-05-08T17:53:24.736605Z","name":"CMC Expertise Comptable","website":"cmcexpertise.fr","address":"32 Rue De La Clairière, Fort-de-France,","description":"CMC Expertise Comptable is a certified accounting firm located in Martinique, dedicated t…Sources
Source
Indexed 3 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

