Ransomware victim disclosure
← All victimsHospice Savannah
Claimed by cmdorganization · listed 3 days ago
Status timeline
- Listed
May 28, 2026
- Data leaked
At a glance
- Group
- cmdorganization
- Status
- Data leaked
- Country
- US
- Sector
- Healthcare
- Listed on leak site
- May 28, 2026
About the victim
AI dossier — public-source company profileHospice Savannah is a healthcare provider offering comprehensive hospice and palliative care services, including specialized pediatric programs and advanced cardiac care. They provide in-home care, nursing home assistance, and inpatient hospice units.
- Industry
- Healthcare - Hospice & Palliative Care
Attack summary
Severity: high — Healthcare provider with patient data at risk; hospice records contain highly sensitive medical and personal information protected under HIPAA. Data publication confirmed by 'data_published' status, though specific proof inventory not detailed.The cmdorganization group claims to have attacked Hospice Savannah and published data. The specific nature of the breach (encryption, exfiltration, or both) and the data categories involved are not detailed in the available post.
Data the group says was taken
AI dossier — extracted from the leak post- Patient records
- Medical information
- Personal health information
What the group claims
Hospice Savannah provides comprehensive hospice and palliative care services to individuals facing serious illnesses, including specialized programs for pediatric patients and advanced cardiac care. Their services extend to in-home care, nursing home assistance, and inpatient hospice units, ensuring a dignified and comfortable end-of-life experience.
Sources
- Victim sitewww.hospicesavannah.org
Source
Indexed 3 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.
