GLOBALMalwareHealthcareHealthcareRansomwareBianlianRansom DemandedActor NamedMedium
Goshen Medical Center
bd_a33c1e431cf7c55a · schema v1 · pii pii-v1
Full breach record for Goshen Medical Center →Threat-actor claim — not a regulatory filing
This row is a claim by the ransomware group BianLian on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Group activity: HealthcareDiscovered: 2025-03-22
Source: Ransomware.live
Post text · scraped from the leak site
Goshen Medical Center is a Federally qualified healthcare organization that offers services at 38 locations in eastern North Carolina.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Ransomware claims (1)
- bd_3e121902466c20bfLeak Sitebianlianfiled 2025-02-15(36d gap)Verified by operator
Regulatory filings (5) · sorted by filing gap
- bd_3f2a93709f58d2eaMontana State AGfiled 2025-09-17(178d gap)Candidate
- bd_5e7d71e199eab35dMaine State AGfiled 2025-09-17(178d gap)Verified by operator
- bd_e392d7437607ec5dVermont State AGfiled 2025-09-17(178d gap)Verified
- bd_18642ee281783b6bSouth Carolina State AGfiled 2025-09-18(179d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 179d gap
- bd_761bf5eafbe89ff2Texas State AGfiled 2025-09-18(179d gap)Verified by operator
Source provenance
- Source URL
- https://www.ransomware.live/
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 22, 2025
- Raw hash
- 1eca91d4061156d36a2e861b174b20e9ac499507354aa1d9c312fbe95e18a5db
Reporting entity
- Name
- bianlian
Victim entity
- Name
- Goshen Medical Centernorm: goshen medical center
- Domain
- goshenmedical.org
- Industry
- Healthcarellm
What this source establishes
- Source ceiling
- A leak-site claim can't tell us: discovery date · materiality · notification · affected count · confirmed data types · compliance clock. These stay blank until a regulatory filing or victim disclosure lands.
- Attack vector
- Ransomware· bianlian
- Threat actor
- BianlianExternalFinancial
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.