Ransomware victim disclosure
← All victimsCareSTL Health
Claimed by cephalus · listed 9 months ago
Status timeline
- Listed
Aug 26, 2025
- Data leaked
At a glance
- Group
- cephalus
- Status
- Data leaked
- Country
- United States
- Sector
- Healthcare
- Listed on leak site
- Aug 26, 2025
About the victim
AI dossier — public-source company profileCareSTL Health is a federally qualified health center (FQHC) that has served the North St. Louis community for more than 50 years. It provides comprehensive, integrated healthcare services across the full spectrum of life—including family practice, pediatrics, behavioral health, dental, women's health, prenatal care, pharmacy, and more—operating multiple clinic locations. The center serves vulnerable and underserved populations on a sliding-fee schedule and accepts Medicaid.
- Industry
- Federally Qualified Health Center (Community Healthcare)
- Address
- North St. Louis, Missouri, United States
Attack summary
Severity: critical — 500+ GB of data exfiltrated and published from a federally qualified health center serving vulnerable populations; data almost certainly includes regulated PHI/PII at scale (medical, behavioral health, prenatal, pediatric), constituting a HIPAA-covered breach. The CEO statement also confirms a 30-day operational disruption, indicating both exfiltration and significant operational impact.The ransomware group 'cephalus' (operating under the KAWA4096 moniker) claims to have exfiltrated over 500 GB of data from CareSTL Health and has published the data. The CEO's site statement references a 30-day operational disruption consistent with a ransomware-related incident, corroborating the attack claim.
Data the group says was taken
AI dossier — extracted from the leak post- Patient medical records
- Behavioral health records
- Prenatal and women's health data
- Pediatric health records
- Insurance and billing information
- Employee/HR records
- Financial and reimbursement data
- Medicaid enrollment data
- Pharmacy records
What the group claims
CareSTL Health DATA Leak | 500+GB | KAWA4096 STEALED our data
Sources
- Victim sitecarestlhealth.org
- Leak posthttps://darkforums.st/Thread-CareSTL-Health-DATA-Leak-500-GB
Source
Indexed 9 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
