BayMark Health Services
September 1, 2024
•[ ransomware, healthcare ]
BayMark Health Services, North America's largest provider of substance use disorder (SUD) treatment and recovery services, notifies an undisclosed number of patients that attackers stole their personal and health information in a September 2024 breach. The RansomHub operation claimed responsibility for the breach.
Hesley Group (UK care provider)
September 1, 2024
•[ hack, healthcare ]
In September 2024, a cyberattack against Hesley Group led to unauthorized access to HR folders, with a small amount of sensitive staff data stolen. Exfiltrated information included PII and employment/medical records (names, contact details, bank details, salary, criminal record, medical data, etc.). No encryption or ransomware involved. The attackers remain unidentified. The incident was publicly disclosed in August 2025 after regulatory notifications.
Australian Cancer Research Foundation
August 30, 2024
•[ leak, healthcare ]
The Australian Cancer Research Foundation (ACRF) sent an email to its donors late on Friday afternoon, 30 August, warning them of a data security incident.
NHS
August 29, 2024
•[ leak, healthcare ]
Several NHS staff in Scotland have had their mobile phone numbers revealed in a cyber security incident involving a third-party supplier to several health boards.
Horizon View Medical Center
August 22, 2024
•[ ransomware, malware, healthcare ]
The Everest ransomware team lists on its data leak site the Nevada-based Horizon View Medical Center and claims to have stolen medical record information, including test results and other sensitive patient data.
AuthoraCare Collective
August 18, 2024
•[ hack, healthcare ]
Between August 1822, 2024, an unauthorized actor accessed AuthoraCare Collectives network, compromising protected health information of approximately 58,019 people. The review concluded on October 21, 2024, and notification letters were issued January 2, 2025. AuthoraCare offered credit monitoring services to those affected.
Chris Leong
August 10, 2024
•[ hack, malware, healthcare ]
In August 2024, the website of Master Chris Leong "a leading Tit Tar practitioner in Malaysia" suffered a data breach. The incident exposed 27k unique email addresses along with names, physical addresses, dates of birth, genders, nationalities and in many cases, links to Facebook profiles. The company did not respond when contacted about the breach.
OnePoint Patient Care
August 8, 2024
•[ ransomware, malware, healthcare ]
OnePoint Patient Care (OPPC) informs customers about a data breach impacting their personal information. The Inc Ransom ransomware group takes credit for the attack. The impact is bigger than initially believed, with over 1.7 million people affected
McLaren Health Care
August 6, 2024
•[ ransomware, malware, healthcare ]
IT and phone systems at McLaren Health Care hospitals are disrupted following an attack linked to the INC Ransom ransomware operation.
Beech Acres Parenting Center
August 5, 2024
•[ hack, leak, healthcare ]
Beech Acres Parenting Center, a nonprofit in Cincinnati, Ohio, reported a data breach involving unauthorized access from AprilAugust 2024 that exposed employee and client personal information, including SSNs and health-related data. No service disruption or encryption was reported.
Bayhealth Hospital
July 31, 2024
•[ ransomware, malware, healthcare ]
The Rhysida Ransomware group claims to have breached Bayhealth Hospital in Delaware and offers alleged stolen data for 25 BTC.
Community Care Alliance
July 29, 2024
•[ ransomware, leak, malware ]
Community Care Alliance is listed in the Rhysida ransomware leak site.
OneBlood
July 29, 2024
•[ ransomware, malware, healthcare ]
OneBlood, a large not-for-profit blood center that serves hospitals and patients in the United States, is dealing with an IT systems outage caused by a ransomware attack.
Delhi Hospital
July 29, 2024
•[ ransomware, leak, malware ]
Delhi Hospital (also known as Richard Parish Hospital) in Louisiana is added to the RADAR and DISPOSSESSORs (R&D) ransomware leak site.
Millinocket Regional Hospital
July 25, 2024
•[ ransomware, malware, healthcare ]
Millinocket Regional Hospital (MRHME) suffers a RansomHub ransomware attack. The threat actors claim to have exfiltrated 10 GB of files.
Schneider Regional Medical Center
July 21, 2024
•[ ransomware, leak, malware ]
Schneider Regional Medical Center in the Virgin Islands is added to Qilins ransomware leak site.
Betances Health Center
July 12, 2024
•[ ransomware, malware, healthcare ]
The ransomware group Hunters International adds Betances Health Center in New York to their leak site.
Rite Aid
July 12, 2024
•[ ransomware, malware, healthcare ]
Pharmacy giant Rite Aid confirms a data breach after suffering a cyberattack in June, which was claimed by the RansomHub ransomware operation. The breach impacts 2.2 million customers.
Sibanye-Stillwater
July 11, 2024
•[ ransomware, malware, healthcare ]
Mining giant Sibanye-Stillwater, one of the worlds biggest producers of platinum and gold, reveals that its global IT systems have suffered a cyberattack. The BlackSuit ransomware gang claims responsibility for the attack.
Florida Department of Health
July 3, 2024
•[ ransomware, malware, healthcare ]
The RansomHub ransomware group claims it breached the Florida Department of Health and gained access to a large amount of potentially sensitive data (100 GB) on Floridians.