Ransomware victim disclosure
← All victimsUnknown (County/Government Entity - US)
Claimed by Rhysida · listed 3 hours ago
Status timeline
- ListedSep 23, 2026
Current state: Listed for ransom
At a glance
- Group
- Rhysida
- Status
- Listed for ransom
- Country
- United States
- Listed on leak site
- Sep 23, 2026
- Data size
- 2.6 TB
- Records
- 814,500 files
About the victim
AI dossier — public-source company profileUnknown US county or government entity in the public health sector. The leaked data includes methadone clinic records, medical assistance files, jail intelligence, and payroll systems, suggesting a multi-department county government operation.
Attack summary
Severity: critical — Confirmed exfiltration of highly regulated sensitive data at scale: methadone clinic records (strictest US confidentiality regime under 42 CFR Part 2), tens of thousands of medical records with diagnoses, 47,602 medical-assistance records with identity documents and SSNs, 721 background checks with full SSNs, and county payroll/pension/discipline records. Multiple categories of regulated PII (healthcare, law enforcement, financial) affecting thousands of individuals.Rhysida claims to have exfiltrated 814,500 files (2.6 TB) from a US county government entity. The group alleges access to highly regulated medical records (methadone clinic data under 42 CFR Part 2), background checks with full SSNs, tens of thousands of medical faxes with patient diagnoses, medical-assistance records with identity documents, payroll registers, and jail gang-intelligence files.
Data the group says was taken
AI dossier — extracted from the leak post- 721 background-check dossiers with SSNs
- Tens of thousands of medical faxes (2022–2026) with patient names and diagnoses
- Methadone clinic records (42 CFR Part 2)
- 47,602 medical-assistance files with driver licenses, Green Cards, SSN cards, tax forms, bank data
- County payroll registers with salaries and HR records
- Pension and discipline databases
- Jail gang-intelligence files and gang-member master list
What the group claims
An unnamed US county or government entity with records including background checks, medical faxes, methadone clinic records under 42 CFR Part 2, medical-assistance files, county payroll, HR records, and jail gang-intelligence files.
The leak post
captured from the group's siteThe Kreishandwerkerschaft Borken is the official trade association and advocacy organization representing local craft enterprises (Handwerksbetriebe) in the Borken district of Germany.1,382,523 files, 1.31 TBhealth data (disability lists with ID numbers, GdB medical ruling with diagnosis)sick leave, absence records, pension ruling2026 payslip (tax ID, social-security no., IBAN) and staff rostersigned contracts/terminations, CV with religionmember and creditor IBANsSCHUFA credit checks, court enforcement order, debtor affidavitMail and databases in full (Exchange, PST, SQL backups) + access/infrastructure slide (2FA secrets, S-FIRM code) With just 7 days on the clock, seize the opportunity to bid on exclusive, unique, and impressive data. Open your wallets and be ready to buy exclusive data. We sell only to one hand, no reselling, you will be the only owner! MPA Pharma GmbH is an internationally active, rapidly growing company specializing in the import and trade of high-quality pharmaceuticals, including both patented and generic products. 2,899,290 files, ~5.8 TBPharmaceutical companyCategories: accounting records and database backups, government audits (customs / corporate tax / …
Data the group says was taken
- background check dossiers
- SSNs
- medical faxes
- patient names and diagnoses
- methadone clinic records
- medical-assistance files
- driver licenses
- Green Cards
- SSN cards
- tax forms
- bank data
- payroll registers
- HR memos
- contracts
- pension databases
- discipline databases
- jail gang-intelligence files
- gang-member master list
Screenshot of the leak post

Sources
Source
Indexed 3 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

