GLOBALMalwareHealthcareHealthcareRansomwareBianlianRansom DemandedActor NamedData Leak ThreatenedData PublishedHigh
Goshen Medical Center
bd_3e121902466c20bf · schema v1 · pii pii-v1
Full breach record for Goshen Medical Center →Threat-actor claim — not a regulatory filing
This row is a claim by the ransomware group BianLian on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Group activity: HealthcareDiscovered: 2025-03-22
Source: Ransomware.live
Post text · scraped from the leak site
Goshen Medical Center is a Federally qualified healthcare organization that offers services at 38 locations in eastern North Carolina.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Ransomware claims (1)
- bd_a33c1e431cf7c55aLeak Sitebianlianfiled 2025-03-22(36d gap)Verified
Regulatory filings (5) · sorted by filing gap
- bd_3f2a93709f58d2eaMontana State AGfiled 2025-09-17(214d gap)Candidate
- bd_5e7d71e199eab35dMaine State AGfiled 2025-09-17(214d gap)Verified by operator
- bd_e392d7437607ec5dVermont State AGfiled 2025-09-17(214d gap)Verified
- bd_18642ee281783b6bSouth Carolina State AGfiled 2025-09-18(215d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 215d gap
- bd_761bf5eafbe89ff2Texas State AGfiled 2025-09-18(215d gap)Verified by operator
Source provenance
- Source URL
- https://www.ransomware.live/id/R29zaGVuIE1lZGljYWwgQ2VudGVyQGJpYW5saWFu
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 15, 2025
- Raw hash
- 144409df0983475cd254501b40c7c7789ca1c23d95592b53f54df4ead8a48087
Reporting entity
- Name
- bianlian
Victim entity
- Name
- Goshen Medical Centernorm: goshen medical center
- Domain
- goshenmedical.org
- Industry
- Healthcare
What this source establishes
- Source ceiling
- A leak-site claim can't tell us: discovery date · materiality · notification · affected count · confirmed data types · compliance clock. These stay blank until a regulatory filing or victim disclosure lands.
- Attack vector
- Ransomware· bianlian
- Threat actor
- BianlianExternalFinancial
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.