Dark Project, an extortion group that has been rapidly adding victims this week, claimed on August 5 that it breached Mile Bluff Medical Center in Mauston, Wisconsin, and posted a download link on the dark web.
The group said it stole more than 550 GB of data, including a full SQL database backup, employee records, bank records, and patient files containing Social Security numbers, medical histories, and surgical records. It put the number of affected patients and staff above 25,000.
Mile Bluff has operated since 1912 and provides acute emergency care as well as long-term nursing and rehabilitation services, making it a typical rural Wisconsin hospital with limited cybersecurity resources. The claim is unconfirmed and the hospital has not commented publicly. The listing was independently logged by ransomware.live, DeXpose, and GalaxyWarden, all of which mark it as unverified.
Rural and critical access hospitals have become favored targets for groups like Dark Project because they hold high-value data and often run lean IT teams. The pattern in these claims is double extortion: encrypt systems, copy records, then threaten to leak what was taken if no payment arrives.
Facilities in this position should treat the claim as real until investigators prove otherwise, inventory what data sits in accessible file shares, test offline backups, and lean on free resources such as CISA and state-based security assistance programs. Rural providers that lack dedicated security staff should also review who has access to SQL backups and patient record stores, since those are the files extortion groups most often weaponize.
