Ransomware victim disclosure
← All victimsWakefield & Associates
Claimed by Knight · listed 2 years ago
Status timeline
- Listed
Nov 30, 2023
- Data leaked
At a glance
- Group
- Knight
- Status
- Data leaked
- Country
- United States
- Sector
- Business Services
- Listed on leak site
- Nov 30, 2023
- Data size
- 400 GB
About the victim
AI dossier — public-source company profileWakefield & Associates, Inc. is a healthcare revenue cycle management (RCM) and collections company headquartered in Knoxville, Tennessee, with additional offices in Aurora, CO, Fort Morgan, CO, and Jefferson City, MO. The company provides billing, collections, and RCM services to healthcare providers, and is partnering with Revco Solutions, Inc. to expand its suite of services. It also handles consumer credit reporting disputes, indicating it operates as a debt collection agency under healthcare finance.
- Industry
- Healthcare Revenue Cycle Management & Collections
- Address
- 320 N Cedar Bluff Road, Suite 300, Knoxville, TN 37923
Attack summary
Severity: critical — Wakefield & Associates handles healthcare RCM and debt collections for healthcare providers, meaning the 400 GB likely contains regulated data including patient financial records, medical billing information, and consumer PII subject to HIPAA and FCRA. Exfiltration at this scale from a healthcare-adjacent financial services firm constitutes a critical disclosure.The Knight ransomware group claims to have exfiltrated over 400 GB of data from Wakefield & Associates and states the victim has refused to negotiate; the group threatens to publish the data to clients, partners, and the public if contact is not made.
Data the group says was taken
AI dossier — extracted from the leak post- Healthcare revenue cycle data
- Patient billing records
- Collections account data
- Consumer credit dispute information
- Client/partner business data
The group's post references roughly 6 proof files.
What the group claims
www.wakeassoc.com We have over 400GB of data from Wakefield and AssociatesThey refuse to come to discuss a deal with us. If you do not contact us soon all this information will be shared to their clients/partners and the world to see.proof 1.jpg 331.01 KBproof 2.jpg 59.34 KBproof 3.jpg 119.89 KBproof 4.jpg 59.26 KBproof 5.jpg 75.65 KBproof 6.jpg 78.77 KB
Sources
Source
Indexed 2 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
