Ransomware victim disclosure
← All victimsSpecial Health Resources
Claimed by Blacksuit · listed 2 years ago
Status timeline
- ListedJun 12, 2024
- Data leakeddate unknown
At a glance
- Group
- Blacksuit
- Status
- Data leaked
- Country
- United States
- Sector
- Healthcare
- Listed on leak site
- Jun 12, 2024
About the victim
AI dossier — public-source company profileSpecial Health Resources (SHR) is a comprehensive healthcare system serving Northeast Texas across 23 counties with clinics in Tyler, Longview, Paris, and Texarkana, plus mobile units. Over two decades old, SHR provides affordable primary care, dental, pediatric, women's health, behavioral health, substance abuse treatment, and HIV/AIDS services, accepting Medicaid, Medicare, and private insurance with income-based fee discounts.
- Industry
- Community Health Centers & Affordable Healthcare
- Address
- Multiple locations: 409 N. 6th St, Longview, TX 75601; 402 N Seventh St, Longview, TX 75601; 4519 Troup Highway, Tyler, TX 75703; plus Paris and Texarkana clinics
Attack summary
Severity: critical — Healthcare provider with confirmed operational disruption and network compromise. Patient data including medical records, PHI, and sensitive behavioral/substance abuse/HIV treatment information at risk. Regulated healthcare data (HIPAA) at scale across multi-county community health system.Blacksuit ransomware group claims to have attacked Special Health Resources. The victim's public website confirms a 'network incident' causing disruption to phones and computer systems, with dental services temporarily unavailable and some services offline.
Data the group says was taken
AI dossier — extracted from the leak post- Patient medical records
- Personal health information (PHI)
- Patient contact information
- Insurance and payment data
- Behavioral health records
- Substance abuse treatment records
- HIV/AIDS screening records
Sources
Source
Indexed 2 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

