Group Health Cooperative - Rev 500kk
bd_9d198d346ee6fe7b · schema v1 · pii pii-v1
Full breach record for Group Health Cooperative - Rev 500kk →Threat-actor claim — not a regulatory filing
This row is a claim by the ransomware group BlackSuit (formerly Royal) on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Source: Ransomware.live
Post text · scraped from the leak site
Patient and member data (MRN numbers, SSN numbers, patient ID, DOB, telephone, EMAIL, residential addresses, information about visits, medical history, various Patient Forms, CLINIC NOTE, scans of diagnoses and examinations with personal data, results of various laboratory tests and Lots of other patient information. Financial documents (balance sheets, budgets, PL reports, audits, statements, transaction reports, cashflow, presentations and many other important financial documents) Employees (ssn numbers, residential addresses, DOB, mail, license numbers, scans of personal documents and much more) Partner database, contracts, NDA forms, I Working documentation (drug db, presentation, reports, various government letters/reports and much more) SQL databases (patient database, employee database, participant database), mail correspondence.
Source provenance
- Source URL
- https://www.ransomware.live/
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 9, 2024
- Raw hash
- 14c5f705021181f67ca5c7fcf356aa6480f5c974bf736da9200379e37537385d
Reporting entity
- Name
- blacksuit
Victim entity
- Name
- Group Health Cooperative - Rev 500kknorm: group health cooperative rev 500kk
- Domain
- ghcscw.com
- Industry
- Healthcarellm
What this source establishes
- Source ceiling
- A leak-site claim can't tell us: discovery date · materiality · notification · affected count · confirmed data types · compliance clock. These stay blank until a regulatory filing or victim disclosure lands.
- Attack vector
- Ransomware· blacksuit
- Threat actor
- BlackSuitExternalFinancial
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.