Ransomware victim disclosure
← All victimsCollege Hospital Costa Mesa
listed as chcm.us · Claimed by Lockbit3 · listed 2 years ago
Status timeline
- ListedSep 26, 2024
- Data leakeddate unknown
At a glance
- Group
- Lockbit3
- Status
- Data leaked
- Country
- United States
- Sector
- Healthcare
- Listed on leak site
- Sep 26, 2024
About the victim
AI dossier — public-source company profileCollege Hospital Costa Mesa is a healthcare facility specializing in psychiatric and medical/surgical services, operating 24/7 crisis stabilization, partial hospitalization programs (PHP), and intensive outpatient services across multiple locations in Los Angeles and Orange Counties, California. The hospital serves both English and Spanish-speaking patients and is accredited by the Center for Improvement in Healthcare Quality (CIHQ).
- Industry
- Healthcare - Psychiatric & Medical/Surgical Services
- Address
- Costa Mesa, California, United States
Attack summary
Severity: high — Healthcare provider with patient data exposure (regulated HIPAA-protected information at scale). Psychiatric hospital records are particularly sensitive. Confirmed data publication by ransomware group.LockBit3 claims to have breached College Hospital Costa Mesa and published data. The group alleges exfiltration of company data, though specific details on data categories are not provided in the truncated leak post.
Data the group says was taken
AI dossier — extracted from the leak post- Patient records
- Medical information
- Company operational data
What the group claims
Greetings! Today we are posting here the new company, "College Hospital Costa Mesa". Company Description: College Hospital Costa Mesa is a facility specializing in psychiatric and medical/surgical services as well as outpatient telehealth, and...
Sources
Source
Indexed 2 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

