Rhysida Ransomware Group Claims 2.44 TB Data Breach at General Santos Doctors Hospital
The Rhysida ransomware group has reportedly listed General Santos Doctors Hospital (GSDH) among its alleged victims, claiming to have stolen approximately 2.44 terabytes of data consisting of more than 3.5 million files.
The claim was displayed on a ransomware leak site and includes a seven-day deadline for the hospital to respond. Rhysida is demanding 8 BTC for the alleged data, stating that the information will be sold if the demand is not met. The listing says the data would be sold exclusively to a single buyer rather than resold to multiple parties.
According to the threat actor's listing, the alleged stolen information covers several major areas of the hospital's operations.
The largest category involves patient and medical information. Rhysida claims the data contains patient records and scans from various hospital departments, including surgical pathology, hemodialysis and admission records. The listing also claims to contain cancer-center dossiers, including records associated with PhilHealth identification numbers, laboratory quotations and cancer-marker testing information containing dates of birth.
The threat actor further claims access to PhilHealth-related claims monitoring information and neonatal intensive care unit (NICU) data, potentially involving highly sensitive information concerning patients and newborns.
The alleged breach also extends beyond patient records. Rhysida claims to have obtained information concerning hospital employees and healthcare professionals, including an accredited physicians register containing cellular numbers, professional licenses and PhilHealth identification numbers.
The listing also claims the presence of payroll workbooks, including those involving an affiliated diagnostic center, as well as human-resources dossiers, passport scans and drug-testing files.
Rhysida's listing also describes a significant amount of alleged financial, accounting and governance information.
The threat actor claims to have obtained audited financial statements, including documents bearing signatures of the hospital's chairman, treasurer or chief financial officer, together with Bureau of Internal Revenue-related documents and balance sheets.
It also claims access to information involving bank accounts across more than six banks, internal audit memoranda concerning alleged cashier discrepancies and cash shortages, and payroll bank-upload batches.
Other corporate information allegedly included in the dataset consists of SEC shareholders' meeting minutes and documents concerning related-party entities stored within the affected network shares. The listing further claims that personal information belonging to senior hospital officials was included in the alleged theft.
Specifically, Rhysida claims to possess mobile phone numbers belonging to the hospital president, hospital administrator and members of the board.
The screenshots accompanying the listing show samples of documents allegedly obtained from the hospital. The visible material appears to include hospital records and other administrative documents.
The figures presented by Rhysida are substantial: 3,502,636 files with an alleged total volume of approximately 2.44 TB.
There is also no information in the displayed listing confirming whether the hospital's systems were encrypted or whether clinical operations were disrupted. The available evidence primarily concerns an extortion/leak-site claim of data theft.
If the claims are ultimately confirmed, the incident could have serious implications because the alleged dataset combines medical records, patient identifiers, employee information, financial records and corporate documents in one collection.
Medical information can be particularly sensitive because it may contain details about a person's medical history, treatment, laboratory results and other private information. The alleged combination with identification, employment, financial and contact information could also increase the potential for identity theft, targeted scams and other forms of abuse.
Rhysida has previously targeted healthcare organizations. Health-ISAC reported in 2023 that Rhysida had attacked healthcare and medical research organizations, while U.S. government agencies subsequently warned that the group had targeted hospitals and other sectors.
Rhysida emerged in 2023 and operates as a ransomware-as-a-service operation. Security researchers have documented the group's targeting of healthcare, government, education and other organizations. FortiGuard described Rhysida as offering its ransomware operation through a RaaS model, while U.S. authorities have warned about its use of stolen information and leak sites as part of its extortion activity.
The use of a leak-site listing allows ransomware operators to pressure victims by publicly announcing an alleged compromise and threatening to release or sell the information if negotiations fail.
Other contents