MPowerHealth Holdings LLC
bd_176e9b2cbf20b3de · schema v1 · pii pii-v1
Full breach record for MPowerHealth Holdings LLC →Press / market disclosure — not a breach-notification filing
A media or market posting that confirms an incident but carries no breach-notification fields, so compliance clocks aren't assessable. The summary below is extracted from the coverage — verify against the source.
MPOWERHealth victim of cyberattack; protected health information involved – DataBreaches.Net. MPOWERHealth: MPOWERHealth was the victim of a 989.8 GB data breach, including protected health information and sensitive data, which were found intact and unencrypted in the recycle bin. The data was obtained by WorldLeaks, which demanded payment in exchange for non-disclosure of the data. MPOWERHealth ceased responding after WorldLeaks refused to negotiate the price. Linked ransomware group: worldleaks.
J jump to incidentP pin to compareR raw source
Incident timeline — mostly unverified
? — ?
Breach window unknown
Jun 29, 2025
Press report
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Attack → press
—
Compliance clock
Not assessable
Linked disclosures
Why this link?Ransomware claims (1)
- Leak Siteworldleaksbd_f3daab487b6c7b362025-08-19 · +52dCandidate
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
Source ceiling
- incident type + narrative only (may be machine-translated)
- discovery date
- materiality
- affected count
- data types
- compliance clock
The ✕ fields stay blank until a regulatory filing or victim disclosure lands.
worldleaks
According to ransomware.live, World Leaks emerged in January 2025 as a rebrand of the Hunters International ransomware operation, shifting its focus from file encryption to solely stealing sensitive data and threatening to leak it unless a ransom is paid