Skip to content

🏥 Healthcare & Life Sciences

Providers, health tech, pharma, biotech, medical devices · a shareable slice of the daily brief for stakeholders who only care about this industry · RSS feed

Victims L30D11▼ −9
Prior 30D20
Active actor L90DQilin · 8
Active actor L90DShinyHunters · 6
Active actor L90DAnubis · 6

Today — 12 Sep 2026

General Santos Doctors Hospital, a 280-bed tertiary hospital in the Philippines, listed on Rhysida's leak site Sep 10.HighHealthcare & Life Sciences🟥 Unverified DLS claim — roughly 3.5M files (2.44TB) allegedly exfiltrated, including name-tagged diagnostic scans, cancer-center records with national health-insurance IDs, and a staff register with professional license numbers; no hospital confirmation yet, verify before treating as a breach. Ransomware.live

Last 14 days

Veradigm confirms unauthorized access to patient data after The Gentlemen ransomware group asserts 3.5M records were taken — attacker used compromised third-party vendor credentials to reach a single API, not a network-wide compromise.CriticalHealthcare & Life SciencesThe Chicago-based EHR/e-prescribing vendor says Social Security numbers were exposed for a subset of customers via a narrow, credential-based access path; no clinical/medical data, servers or broader network were touched, and operations weren't disrupted. The Gentlemen posted Veradigm to its data-leak site Sep 5 with a Sep 11 publication deadline absent a ransom negotiation. Veradigm confirms the access itself; the 3.5M-record scope is the attacker's own figure. BleepingComputer
A Fortune-class healthcare vendor compromised through a single vendor credential and a narrow API scope, rather than a network-wide intrusion, continues 2026's structural theme: the weakest point in large enterprises' security posture is increasingly a specific third-party access path, not the core network.MediumHealthcare & Life SciencesVeradigm's containment (no clinical data, no server/network compromise) is what a mature incident-response posture looks like when the blast radius is architecturally limited — worth noting precisely because so many of this year's headline breaches (McKesson, Trezor/ShipMonk) show the opposite pattern. Segmenting vendor and partner API access remains the highest-leverage healthcare-sector control available today. BleepingComputer
McKesson/ShinyHunters — Sep 9 data-publication deadline is today; no public resolution confirmed as of this writing.CriticalHealthcare & Life SciencesThe Sep 1 contact deadline passed without engagement, and ShinyHunters' operative threat is to publish the claimed haul today. 🟥 The 284M-record figure remains the attacker's own characterization of raw Salesforce/Snowflake rows, not a unique-patient count; McKesson has not disclosed a number. A publication today would be the largest US healthcare breach-notification event of 2026. SecurityWeek · CyberScoop
ShinyHunters runs the same playbook twice in one week against very different targets — a Fortune 10 healthcare distributor and a state DMV — underscoring that its methodology (social-engineer or password-reset your way to a data store, then extort) doesn't require a specific tech stack.HighGovernment & Public SectorHealthcare & Life SciencesMcKesson via voice-phished Okta SSO into Salesforce/Snowflake; Florida DAVID via a password-reset flaw. See Intelligence Agency Alerts above for the group's other current AI-related news cycle context. BleepingComputer
McKesson's Sep 9 deadline is the second major US healthcare extortion clock to run out this quarter, and healthcare's specific vulnerability is structural, not incidental: third-party SaaS sprawl (Salesforce, Snowflake) now sits between the industry's HIPAA obligations and its actual attack surface.HighHealthcare & Life SciencesVoice-phishing a help desk into resetting SSO credentials bypasses most of the technical controls healthcare compliance programs are built around, because the weak point is a human process, not a system. Expect this incident, if data publishes today, to accelerate the same vendor-risk-audit conversation already underway after Trezor/ShipMonk — but for identity providers and CRM/data-warehouse vendors specifically rather than fulfillment partners. SecurityWeek
McKesson / ShinyHunters — Sep 9 publication deadline one day out; no public resolution signalHighHealthcare & Life SciencesAs of Sep 8, McKesson has made no statement on payment or negotiation status. The Sep 1 contact deadline passed without public engagement; Sep 9 is the operative data-publication threshold ShinyHunters has set. 🟥 The 284M-record figure remains ShinyHunters' own characterization; unique-individual count unverified. A publication would be the largest US healthcare breach-notification event of 2026. SecurityWeek · CyberScoop
Boston Scientific — no material change since Sep 7; shipping restoration continuing toward Piper Sandler's mid-September estimate.MediumHealthcare & Life SciencesIndustrials & ManufacturingMajor distribution centers have resumed shipping for most products; Cork remains at reduced capacity. No new intrusion activity reported since Aug 25. MedTech Dive
McKesson / ShinyHunters — Sep 9 publication deadline 2 days out; no resolution signal; 284M-record publication would be the largest US healthcare breach notification event of 2026HighHealthcare & Life SciencesAs of Sep 7, McKesson has made no public statement on payment or resolution. ShinyHunters' Sep 9 data-publication deadline is the operative threshold. The Sep 1 contact deadline passed without McKesson public engagement. 🟥 The 284M-record count is ShinyHunters' own characterisation; unique-individual figure unverified. A publication triggers OCR breach investigation, state AG enforcement, class actions across multiple jurisdictions, and Senate Commerce Committee scrutiny. SecurityWeek · CyberScoop
Boston Scientific — Day 13 of recovery; no new adverse network activity; Cork manufacturing remains at reduced capacityMediumHealthcare & Life SciencesIndustrials & ManufacturingNo material change since Sep 6. Distribution shipping restored at major global centres; Cork site partially restored. CrowdStrike and third-party experts leading investigation confirm no new intrusion activity since Aug 25. Piper Sandler mid-September full-restoration estimate unchanged. 🟥 Threat actor and attack vector not publicly disclosed. Boston Scientific · SecurityWeek
McKesson / ShinyHunters — Sep 9 data-publication deadline 3 days out; $55M demand unanswered; no public settlement signalCriticalHealthcare & Life SciencesAs of Sep 6, McKesson has not confirmed payment or resolution. ShinyHunters has not published the claimed 284M-record Snowflake exfiltration (attack window Aug 21–25, vishing → Okta SSO → multi-SaaS pivot). The initial Sep 1 negotiation deadline passed without public McKesson engagement; the Sep 9 publication deadline is the operative threshold. 🟥 The 284M-record count is ShinyHunters' own characterisation; unique-individual figure TBD. SecurityWeek · Malwarebytes
Boston Scientific — Day 13 recovery; no new adverse network activity since Aug 25; mid-September full-restoration estimate unchangedHighHealthcare & Life SciencesIndustrials & ManufacturingNo material change from Sep 5. Shipping capabilities restored for the majority of product lines at major distribution centres globally; Cork manufacturing remains at reduced capacity. The Piper Sandler mid-September restoration estimate stands. 🟥 Threat actor and attack method not disclosed; no confirmed data exfiltration. Hospital procurement planners for elective cardiac procedures should continue contingency sourcing. Boston Scientific · SecurityWeek
McKesson's Sep 9 silence is itself an intelligence signal: either a private resolution is in progress at or above $55M, or a healthcare-data publication of 284M records in the next 72 hours will trigger the largest US healthcare breach notification event of 2026.HighHealthcare & Life SciencesEither outcome reshapes the structural economics of US healthcare extortion. A disclosed payment sets a $55M price floor for the next attacker targeting a major US healthcare distributor — and every distributor knows who the other McKesson-scale players are. A publication triggers state AG enforcement actions, class actions in multiple jurisdictions, OCR breach investigation, and Senate Commerce Committee scrutiny. The vishing+Okta+Snowflake attack chain is now documented and repeatable; ShinyHunters demonstrated it at scale in 2024 against Snowflake customers, and the McKesson operation shows the methodology survives platform security improvements. SecurityWeek · ExZec Cyber

Recent victim claims

Newest first, mapped to this industry from the victim database. Most are leak-site claims — verify before acting.

September 2026

Sep 10 General Santos Doctors Hospital Rhysida Ransomware · healthcare · Philippines Rhysida lists a 280-bed Level 3 tertiary hospital in South Cotabato, claiming roughly 3.5M files (2.44TB) exfiltrated including name-tagged diagnostic scans, cancer-center records with PhilHealth IDs, lab quotations with birth dates, and a staff register with PRC license numbers. No hospital confirmation yet; verify before treating as a breach. · Sources: Ransomware.live
Sep 08 Veradigm The Gentlemen Ransomware · healthcare technology · US Chicago-based EHR/e-prescribing/practice-management vendor confirms an attacker used compromised third-party vendor credentials to access a specific Veradigm API and download patient data, including Social Security numbers for a subset of customers; no clinical/medical data, network or server compromise. The Gentlemen posted Veradigm to its leak site Sep 5, asserting 3.5M patient records (names, addresses, SSNs, emails, phones) were taken, and set a Sep 11 publication deadline absent ransom negotiation. The access itself is company-confirmed; the 3.5M-record scope is the attacker's own figure. · Sources: BleepingComputer · The Record
Sep 03 DiaSorin S.p.A. Settra Ransomware · Healthcare / Diagnostics · Italy Settra DLS claim Sep 3 2026; Italian in vitro diagnostics multinational (EURONEXT Milan: DIA); data scope and volume not disclosed. 🟥 Unverified DLS claim. · Sources: https://www.dexpose.io/settra-ransomware-attack-on-diasorin-s-p-a/
Sep 03 MedEvolve Settra Ransomware · Healthcare · USA Settra DLS claim Sep 3 2026; US medical billing and practice management software provider; ~820GB exfiltrated; estimated attack date Aug 11 2026. 🟥 Unverified DLS claim. · Sources: https://www.dexpose.io/settra-ransomware-attack-on-medevolve/

August 2026

Aug 25 National Kidney Registry Direwolf Ransomware · Healthcare · US Organ donor-recipient matching nonprofit; DLS claim Aug 25. Five healthcare victims for Direwolf in 16 days. 🟥 Unverified DLS claim. · Sources: https://www.ransomware.live/group/direwolf
Aug 25 McKesson Corporation ShinyHunters Extortion · Healthcare · USA ShinyHunters claimed theft of 284M patient data records via third-party application compromise; McKesson confirmed the incident in an SEC 8-K and launched investigation; data allegedly includes names, SSNs, DOBs, patient IDs, Medicaid numbers, medical records, medications — 284M is raw record count, unique individual count TBD; claim unverified · Sources: https://www.bleepingcomputer.com/news/security/mckesson-discloses-breach-after-shinyhunters-claims-patient-data-theft/
Aug 25 Boston Scientific Unknown Ransomware · Healthcare · USA Cyberattack caused global IT disruption; systems supporting order processing and shipment affected; Cork Ireland manufacturing facility workers sent home; investigation by third-party incident response firm ongoing; actor unattributed; timeline for restoration unknown · Sources: https://techcrunch.com/2026/08/26/medical-device-maker-boston-scientific-says-a-cyberattack-is-causing-a-global-disruption-to-its-operations/
Aug 22 NovoCure ShinyHunters Extortion · Healthcare / Medical Devices · USA ShinyHunters DLS claim Aug 22 2026; NovoCure (NYSE: NVCR) makes Tumor Treating Fields cancer-treatment devices; data scope and deadline not publicly confirmed; 🟥 unverified DLS claim · Sources: RansomLook
Aug 22 Integrated Health Systems CoinbaseCartel Ransomware · Healthcare · USA CoinbaseCartel DLS claim Aug 22 2026; Integrated Health Systems (ihs911.com) is a US healthcare provider; data-theft extortion with 48h contact window, 10-day payment deadline; data scope unconfirmed; 🟥 unverified DLS claim · Sources: DEXpose
Aug 20 Hospital for Sick Children (SickKids) Unknown Ransomware · Healthcare · Canada Employee and job-applicant personal data exposed via vulnerability in unnamed third-party careers website software; clinical systems and patient data not affected; SickKids, Boomerang Health, SickKids Foundation employees and applicants impacted; vendor unnamed suggesting wider supply-chain exposure · Sources: CP24 · BleepingComputer · The Record
Aug 14 Baxter International ShinyHunters Extortion · Healthcare / Medical Technology · USA ShinyHunters DLS claim August 14 2026 against Baxter International; 7.1 million Salesforce records with PII claimed; extortion deadline was August 17; as of August 22 no data has been published · Sources: https://www.hookphish.com/blog/ransomware-group-shinyhunters-hits-baxter-international-inc/
Aug 13 SIA Medical Centre Rhysida Ransomware · Healthcare · AU Rhysida DLS claim August 13, 2026; SIA Medical Centre Melbourne; scope unconfirmed. · Sources: https://www.ransomware.live/group/rhysida
Aug 13 Philips Clop Extortion · Healthcare Technology · NLD Clop listed Philips on DLS in mass PTC Windchill/FlexPLM campaign (CVE-2026-12569); claimed 13.5GB of PDF drawings, diagrams and blueprints. Philips confirmed an investigation is underway. DLS claim — breach not confirmed. · Sources: https://www.technadu.com/shell-and-philips-confirm-investigation-following-cl0p-data-theft-claims-targeting-nearly-50-companies-including-fiserv-and-ge/633182/
Aug 10 Unlimited Technology Systems Unknown Ransomware · Healthcare Technology · US Ohio-based healthcare revenue cycle management firm; breach Oct 5-10 2025; detected Oct 19 2025; HHS OCR notification filed late July 2026 confirming 3,803,750 individuals affected; SSNs DOBs medical/insurance data stolen; largest healthcare breach of 2026 YTD by victim count · Sources: https://www.securityweek.com/3-8-million-impacted-by-unlimited-technology-systems-data-breach/
Aug 10 Quironsalud Direwolf Ransomware · Healthcare · Spain Spain's largest private hospital group (50+ hospitals, ~13,000 beds). Attack discovered Aug 10; DLS claim Aug 10-11. 🟥 Unverified DLS claim. · Sources: https://www.dexpose.io/direwolf-ransomware-attack-on-quironsalud-spains-health-giant/
Aug 04 BLACKBURN's Physicians Pharmacy Anubis Ransomware · Healthcare / Pharmacy · US Anubis ransomware DLS claim approximately August 3-4 2026; US healthcare pharmacy; no statement from BLACKBURN's; data scope and impact unconfirmed · Sources: https://www.ransomware.live/
Aug 03 Amgen Unknown Ransomware · Pharmaceutical / Biotech · US Unauthorized access to third-party cloud systems detected July 2026; PHI and proprietary company data exfiltrated; Amgen disclosed via SEC 8-K filing approximately August 3; forensic investigation ongoing; no patient count disclosed; no operational disruption reported; no threat actor claimed credit · Sources: https://therecord.media/amgen-hackers-cyberattack-sec https://www.bleepingcomputer.com/news/security/amgen-says-cloud-data-breach-exposed-patient-health-proprietary-info/
Aug 03 Cameron Regional Medical Center Anubis Ransomware · Healthcare · US Anubis ransomware DLS claim August 3 2026; regional US medical centre; no statement from Cameron Regional; data scope and impact unconfirmed · Sources: https://www.ransomware.live/
Aug 02 ProHealth Medical Group Krybit Ransomware · Healthcare · Singapore Krybit DLS claim August 2: 114 GB of data claimed exfiltrated from Singapore healthcare provider ProHealth Medical Group Pte Ltd (prohealth.sg). Patient and operational data scope unconfirmed; no victim statement. 🟥 DLS claim only. · Sources: https://www.dexpose.io/krybit-ransomware-targets-singapores-prohealth-medical-group/ · https://www.redpacketsecurity.com/krybit-ransomware-victim-www-prohealth-sg/
Aug 02 ProHealth Medical Group Pte Ltd Krybit Ransomware · Healthcare · SGP Krybit ransomware posted DLS claim Aug 2; 114GB data claimed from Singapore primary healthcare provider (11 clinics). Krybit also targeted Actini Group (France) Aug 10. · Sources: https://www.dexpose.io/krybit-ransomware-targets-singapores-prohealth-medical-group/
Aug 01 Alcon Inc. ShinyHunters Extortion · Medical Devices / Ophthalmology · Switzerland ShinyHunters DLS posting August 1 2026 with August 4 contact deadline; claims 25M+ Salesforce records with PII; Alcon is a global ophthalmology medical device and pharmaceutical company; no statement from Alcon; data not yet published · Sources: https://www.redpacketsecurity.com/shinyhunters-ransomware-victim-alcon-inc/ https://www.dexpose.io/shinyhunters-breach-alcon-inc/
Aug 01 Lumenis Ltd. ShinyHunters Extortion · Medical Devices / Laser Systems · Israel ShinyHunters DLS posting August 1 2026 with August 4 contact deadline; claims 1.1M+ customer and employee records plus 176 GB internal corporate data; Lumenis manufactures surgical and aesthetic laser systems; no statement from Lumenis; data not yet published · Sources: https://www.redpacketsecurity.com/shinyhunters-ransomware-victim-lumenis-ltd/ https://breachnews.com/breaches/shinyhunters-lists-questel-alcon-and-lumenis-on-leak-site-with-new-extortion-claims/

July 2026

Jul 31 Hawaii Family Dental Qilin Ransomware · Healthcare · US Qilin posted Hawaii Family Dental on DLS July 31; dental healthcare provider; Qilin exploiting CVE-2026-0257 (PAN-OS GlobalProtect) as primary initial access; 1358+ cumulative Qilin victims · Sources: https://www.ransomware.live/ https://cybersecuritynews.com/qilin-ransomware-claims-1358-victims/
Jul 28 Affinia Healthcare Termite Ransomware · Healthcare · US St. Louis multidisciplinary medical system; Termite ransomware DLS posting July 28 2026; class action investigation opened; data scope unconfirmed; 🟥 unverified DLS claim · Sources: https://www.redpacketsecurity.com/termite-ransomware-victim-affinia-healthcare/
Jul 27 MCBS (Medical Computer Business Services) PEAR Ransomware · Healthcare · US Healthcare revenue cycle management firm; 1,261,464 patients exposed across 7 healthcare providers; 3TB data allegedly exfiltrated; 5-day compromise Sep 22-26 2025; not detected until May 28 2026; PEAR operates without encryption (pure extortion) · Sources: https://www.securityweek.com/mcbs-data-breach-affects-1-2-million-individuals/
Jul 25 Principle Diagnostics Laboratory Qilin Ransomware · Healthcare · Unknown DLS posting July 25 2026 by Qilin. Diagnostic laboratory; sector confirmed, country unconfirmed. · Sources: https://www.ransomware.live/
Jul 25 AnMed Health System Unknown Ransomware · Healthcare · US 79 of 106 facilities closed including oncology, radiation, infusion, and imaging services; 72-hour ransom demand issued; FBI and SLED investigating; class action investigations underway · Sources: https://www.hipaajournal.com/anmed-closes-almost-80-facilities-while-it-grapples-with-cyberattack/ · https://www.healthcareitnews.com/news/anmed-given-72-hours-respond-demands-ransomware-incident
Jul 23 LAXAI Life Sciences Krybit Ransomware · pharmaceutical / CDMO · India Krybit DLS claim July 23, 2026; LAXAI Life Sciences Pvt. Ltd. is a Contract Research, Development, and Manufacturing Organization (CRDMO) based in India; data scope and impact unconfirmed; 🟥 unverified · Sources: https://www.dexpose.io/krybit-ransomware-targets-laxai-life-sciences-in-india/ · https://www.cyfirma.com/news/weekly-intelligence-report-31-jul-2026/
Jul 20 Advantage Home Health Care The Gentlemen Ransomware · healthcare · US US home healthcare company claimed by The Gentlemen extortion group July 20; no confirmation from organization · Sources: https://www.ransomware.live/
Jul 18 Droguería Martorani Qilin Ransomware · healthcare (pharmaceutical distribution) · Argentina Argentine medical and hospital products importer/distributor, Buenos Aires; Qilin DLS claim Jul 18, 2026; founded 1970 by Luis Alberto Martorani; distributes medical equipment nationally; 🟥 unverified · Sources: https://ransomware.live/id/RHJvZ3VlcsOtYSBNYXJ0b3JhbmlAcWlsaW4=
Jul 18 Abbott Laboratories (Exact Sciences) ShinyHunters Extortion · healthcare (medical devices / cancer diagnostics) · US Abbott confirmed Jul 18, 2026 unauthorized access to limited systems in Cancer Diagnostics (Exact Sciences) business; ShinyHunters DLS claim alleges exfil of Microsoft Entra/ServiceNow/SharePoint/Databricks/Coupa data; claims: 30M+ rows customer PII, 1M+ SSNs, 22M+ medical order records, doctor-patient notes, NDAs; DLS deadline extended to Jul 21; ShadowByt3$ claims separate LabCentral portal breach under parallel investigation; Abbott has not confirmed data theft scope; 🟥 unverified · Sources: https://www.bleepingcomputer.com/news/security/abbott-laboratories-probes-two-cyber-incidents-amid-extortion-claims/ · https://cybernews.com/news/abbott-laboratories-breach-shinyhunters/ · https://www.abbott.com/en-us/corpnewsroom/diagnostics-testing/abbott-statement-on-cyber-incident-in-cancer-diagnostics-business
Jul 08 Dignity Health St. Mary's Medical Center Akira Ransomware · healthcare · hospital/US acute-care hospital (232 beds); Akira DLS claim April 2026; 41 GB claimed including employee passports, SSNs, government IDs, contracts, NDAs; victim notification letters sent July 2026; attack date estimated April 2026; 🟥 unverified — hospital has not issued public statement confirming breach · Sources: [ClassAction.org] · [BleepingComputer]
Jul 08 Aesthetic Surgical Images INC Ransom Ransomware · healthcare · plastic surgery/US INC Ransom DLS claim July 8, 2026; data scope and impact unconfirmed; 🟥 unverified · https://sharkstriker.com/blog/ransomware-roundup/ · https://www.ransomware.live/group/incransom · Sources: [SharkStriker] · [ransomware.live]
Jul 08 Shanghai Xuerong Biotechnology Co., Ltd. KRYBIT Ransomware · biotechnology · China KRYBIT DLS claim July 8, 2026; data scope and impact unconfirmed; 🟥 unverified · https://sharkstriker.com/blog/ransomware-roundup/ · https://www.ransomware.live/group/krybit · Sources: [SharkStriker] · [ransomware.live]
Jul 07 Next Clinics Qilin Ransomware · healthcare · US Qilin DLS claim July 7, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/qilin · Sources: [ransomware.live]
Jul 06 Asisken Wallstreet Ransomware · medical assistance · unknown Wallstreet DLS claim July 6, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/wallstreet · Sources: [ransomware.live]
Jul 04 Baraga County Memorial Hospital Wallstreet Ransomware · healthcare · US Baraga County Memorial Hospital in L'Anse, Michigan; Wallstreet DLS claim July 4, 2026; data scope and impact unconfirmed; attack in reduced-staffing US Independence Day holiday window; 🟥 unverified · https://www.ransomware.live/ · Sources: [ransomware.live]
Jul 04 Abbott Laboratories (LabCentral) ShadowByt3dollar Ransomware · Healthcare / Medical Devices · USA API exfiltration of LabCentral customer portal from July 4; actor claims CE certificates, manufacturing specs, regulatory documents. Distinct from ShinyHunters Exact Sciences SSO incident (seq 478). Abbott investigating both simultaneously. · Sources: https://www.bleepingcomputer.com/news/security/abbott-laboratories-probes-two-cyber-incidents-amid-extortion-claims/
Jul 02 DISS Krybit Ransomware · medical technology · US Krybit DLS claim July 2, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/krybit · Sources: [ransomware.live]
Jul 02 Colorado Rehabilitation & Occupational Medicine INC Ransom Ransomware · healthcare · US Colorado-based rehabilitation and occupational medicine practice; INC Ransom DLS claim July 2, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/incransom · Sources: [ransomware.live]
Jul 02 Quest Healthcare Solutions Anubis Ransomware · healthcare · US employee data and internal files claimed exfiltrated; Anubis DLS claim July 2, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.hendryadrian.com/ransom-quest-healthcare-solutions-jul-2026/ · https://www.ransomware.live/group/anubis · Sources: [hendryadrian.com] · [ransomware.live]
Jul 01 Azienda Ospedaliera Moscati Krybit Ransomware · healthcare · Italy Italian public hospital; Krybit DLS claim July 1, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/krybit · Sources: [ransomware.live]
Jul 01 Centre Ophtalmologique d'Ermont The Gentlemen Ransomware · healthcare · ophthalmology/France French ophthalmology centre; The Gentlemen DLS claim July 1, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.breachsense.com/breaches/2026/july/ · Sources: [Breachsense]
Jul 01 Golden State Orthopedic Brain Cipher Ransomware · healthcare · orthopedics/US orthopedic healthcare provider; Brain Cipher DLS claim July 1, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/ · Sources: [DeXpose]

June 2026

Jun 30 Primed Halberstadt Medizintechnik GmbH Aur0ra Ransomware · medical devices · Germany German manufacturer of medical devices (founded 1946; part of PE-backed PP Medtech group); Aur0ra DLS claim June 30, 2026; data scope and impact unconfirmed; 🟥 unverified · https://ransomware.live/id/UHJpbWVkIEhhbGJlcnN0YWR0IE1lZGl6aW50ZWNobmlrQGF1cm9yYQ== · Sources: [ransomware.live]
Jun 30 PAI Pharma Brain Cipher Ransomware · pharmaceuticals · US Brain Cipher DLS claim June 30, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/braincipher · Sources: [ransomware.live]
Jun 30 Boston Orthotics & Prosthetics Anubis Ransomware · healthcare · orthotics-prosthetics/US leading employee-owned orthotics and prosthetics provider with multiple clinic locations across the northeastern US; ANUBIS DLS claim June 30, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/anubis · https://www.breachsense.com/breaches/2026/june/ · Sources: [ransomware.live] · [Breachsense]
Jun 30 ESMS Global Anubis Ransomware · healthcare services · UK specialised healthcare services company; ANUBIS DLS claim June 30, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/anubis · https://www.breachsense.com/breaches/2026/june/ · Sources: [ransomware.live] · [Breachsense]
Jun 30 Medlink Georgia CMD Ransomware · healthcare · federally qualified health center/US federally qualified health center providing comprehensive care with sliding-fee scale for uninsured and underinsured patients; CMD DLS claim June 30, 2026; sensitive data threatened for release unless negotiations initiated; data scope and impact unconfirmed; 🟥 unverified — no Medlink Georgia public statement · https://www.dexpose.io/cmdorganization-strikes-medlink-georgia-in-latest-ransomware-attack/ · https://ransomware.live/id/TWVkbGluayBHZW9yZ2lhQGNtZG9yZ2FuaXphdGlvbg== · Sources: [DeXpose] · [ransomware.live]
Jun 29 NASCO Qilin Ransomware · healthcare technology · US NASCO provides Blue Cross Blue Shield plan administrative data processing for multiple BCBS plans nationwide; Qilin DLS claim June 29, 2026; data scope unconfirmed; 🟥 unverified — verify before treating as a breach · https://www.ransomware.live/group/qilin · Sources: [ransomware.live]
Jun 29 Bristol Place Corporation Qilin Ransomware · healthcare services · US family-owned healthcare services organization; Qilin DLS claim June 29, 2026; data scope and impact unconfirmed; 🟥 unverified · https://ransomware.live/id/QnJpc3RvbCBQbGFjZUBxaWxpbg== · https://www.breachsense.com/breaches/2026/june/ · Sources: [ransomware.live] · [Breachsense]
Jun 29 Clínica La Sabana Payload Ransomware · healthcare · clinic/Colombia Colombian medical clinic; Payload DLS claim June 29, 2026; data scope and impact unconfirmed; 🟥 unverified — no victim statement · https://www.breachsense.com/breaches/2026/june/ · https://www.ransomware.live/group/payload · Sources: [Breachsense] · [ransomware.live]
Jun 28 Hologic, Inc. REDACT Ransomware · medical devices · healthcare technology/US global medical technology company (~$4B revenue; breast health, diagnostics, GYN surgical products); REDACT DLS claim June 28, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.redpacketsecurity.com/redact-ransomware-victim-hologic/ · Sources: [RedPacket Security]
Jun 26 Clearview Eye Centre Interlock Ransomware · healthcare · ophthalmology/Canada ophthalmic clinic and eye care centre; Interlock DLS claim June 26, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/interlock · https://www.dexpose.io/interlock-ransomware-attack-on-clearview-eye-centre/ · Sources: [ransomware.live] · [DeXpose]
Jun 25 ISOPLUS Qilin Ransomware · pharmaceuticals · Greece Greek pharmaceutical company; Qilin DLS claim June 25, 2026; data scope and impact unconfirmed · https://www.dexpose.io/qilin-ransomware-targets-greek-pharma-leader-isoplus/ · https://www.hendryadrian.com/ransom-isoplus-jun-2026/ · Sources: [DeXpose] · [hendryadrian.com]
Jun 24 Quest Health Solutions Anubis Ransomware · healthcare · US 239 GB of sensitive operational data claimed exfiltrated including employee data, internal files, and additional undisclosed materials; Anubis announced attack June 24, 2026, and threatened to publish data within 2-3 days; Go-based malware with dual-threat encryption and wipe model; Quest Health Solutions has not issued a public statement · https://www.dexpose.io/anubis-ransomware-group-targets-quest-health-solutions/ · https://www.hookphish.com/blog/ransomware-group-anubis-hits-quest-health-solutions/ · https://www.ransomware.live/id/UXVlc3QgSGVhbHRoIFNvbHV0aW9uc0BhbnViaXM · Sources: [DeXpose] · [HookPhish] · [ransomware.live]
Jun 23 Horizon Eye Care INC Ransom Ransomware · healthcare · ophthalmology/US comprehensive eye exam and corrective-vision services provider (LASIK, cataract, contact lens, designer eyewear); DLS claim June 23; data scope and impact unconfirmed; no Horizon Eye Care statement · https://www.redpacketsecurity.com/incransom-ransomware-victim-horizoneye-com/ · https://www.ransomware.live/group/incransom · Sources: [RedPacket Security] · [ransomware.live]
Jun 22 Hooke Laboratories The Gentlemen Ransomware · biotechnology · US preclinical contract research supplier specialising in autoimmune disease model kits (Hooke Kits) used by academic and pharma research laboratories; The Gentlemen DLS claim June 22, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.redpacketsecurity.com/thegentlemen-ransomware-victim-hooke-laboratories/ · https://www.ransomware.live/id/SG9va2UgTGFib3JhdG9yaWVzQHRoZWdlbnRsZW1lbg== · https://www.breachsense.com/breaches/hooke-laboratories-data-breach/ · Sources: [RedPacket Security] · [ransomware.live] · [Breachsense]
Jun 22 Xsolis, Inc. Unattributed Breach · healthcare technology (utilization management · revenue cycle)/US 1,396,519 individuals; names, DOB, addresses, SSNs, health insurance info, medical treatment data; phishing attack January 20, 2026, detected January 22; actor unattributed · https://www.securityweek.com/xsolis-data-breach-affects-1-4-million-individuals/ · https://www.hipaajournal.com/xsolis-data-breach/ · https://databreaches.net/2026/06/22/xsolis-breach-affected-1396519-of-its-clients-patients/ · Sources: [SecurityWeek] · [HIPAA Journal] · [DataBreaches.net]
Jun 20 Central Florida Cosmetic & Family Dentistry Qilin Ransomware · healthcare · US Sources: ransomware.live DLS

← All industries · Victim database →