Deaconess Health System
bd_50e717ff643a8569 · schema v1 · pii pii-v1
Full breach record for Deaconess Health System →5 incidents on fileThreat-actor claim — not a regulatory filing
This row is a claim by the ransomware group Worldleaks on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Source: Ransomware.live
Post text · scraped from the leak site
Deaconess Health System is a nonprofit regional health care organization based in Evansville, Indiana, United States. It operates hospitals, clinics, and specialty care centers across the tri-state area of Indiana, Illinois, and Kentucky. Services include emergency care, oncology, cardiology, orthopedics, and behavioral health. Founded in 1892, it remains one of the largest employers in southwestern Indiana.
J jump to incidentP pin to compareR raw source
Incident timeline — mostly unverified
? — ?
Breach window unknown
Jan 7, 2026
Claim posted
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Claim → filing
—
Compliance clock
Not assessable
Linked disclosures
Why this link?Ransomware claims (1)
- Leak Siteworldleaksbd_ee3310a1c914a30f2026-04-08 · +91dVerified by operator
Regulatory filings (4) · sorted by filing gap
- Illinois State AGbd_4bda20dfe4268b022026-03-01 · +53dVerified by operator
- HHS OCRbd_db347d72095d5b102026-03-20 · +72dVerified
- Illinois State AGbd_e8a3fe09c3056b5c2026-08-01 · +206dVerified
- Texas State AGbd_7ad004d4210ef67d2026-08-07 · +212dVerified by operator
Filing propagation · 5 filings · 3 states
View merged incident ↗Pattern: first filing Jan 7, last Aug 7 (TX) — a 212-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
Source ceiling
- actor name
- victim claim
- ransom/leak status
- discovery date
- materiality
- notification
- affected count
- confirmed data types
- compliance clock
The ✕ fields stay blank until a regulatory filing or victim disclosure lands.
worldleaks
According to ransomware.live, World Leaks emerged in January 2025 as a rebrand of the Hunters International ransomware operation, shifting its focus from file encryption to solely stealing sensitive data and threatening to leak it unless a ransom is paid