GLOBALMalwareHealthcareHealthcareRansomwareLapsus$LapsusRansom DemandedActor NamedMedium
VirtaHealth
bd_0a26e18c6ccacb30 · schema v1 · pii pii-v1
Full breach record for VirtaHealth →Threat-actor claim — not a regulatory filing
This row is a claim by the ransomware group Lapsus$ on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Group activity: HealthcareDiscovered: 2026-04-05
Source: Ransomware.live
Post text · scraped from the leak site
Healthcare research
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_adcafdeb213f7355HHS OCRfiled 2026-05-23(55d gap)Verified
Source provenance
- Source URL
- https://www.ransomware.live/
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 29, 2026
- Raw hash
- 3d9e8ba238f40ccd1ada818e5bfacc2e2b012ebb37288f3944095490c7dfc865
Reporting entity
- Name
- lapsus$
Victim entity
- Name
- VirtaHealthnorm: virtahealth
- Domain
- virtahealth.com
- Industry
- Healthcare
What this source establishes
- Source ceiling
- A leak-site claim can't tell us: discovery date · materiality · notification · affected count · confirmed data types · compliance clock. These stay blank until a regulatory filing or victim disclosure lands.
- Attack vector
- Ransomware· lapsus$
- Threat actor
- Lapsus$ExternalFinancial
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.