A ransomware crew is claiming a multi-terabyte trove of clinical, staff and payroll files from a hospital in the southern Philippines.
Rhysida says it lifted 3.5 million files, about 2.44 TB, from General Santos Doctors Hospital. Leak-site monitors logged the listing on September 10 and classified the victim as healthcare. The gang’s own description is unusually granular: name-tagged pathology scans, hemodialysis charts, admission records, neonatal intensive care data, and cancer-center dossiers carrying PhilHealth identifiers. It also points to lab quotations for cancer-marker tests, an accredited physicians register holding mobile numbers, professional licence numbers and PhilHealth IDs, named payroll workbooks, staff passport scans, and audited financial statements signed by the hospital’s chairman, treasurer and chief financial officer.
The hospital has not confirmed the intrusion or the data claims, and the listing is an extortion assertion rather than a verified finding.
Rhysida has stayed busy across healthcare this year, with earlier claims involving a California clinic network, a Melbourne practice group and a dental chain. The Philippines mix of digitized and scanned paper records makes the exposure harder to unwind: PhilHealth identifiers cannot be reissued, and clinical scans often sit outside the systems covered by an electronic records audit trail.