Rhysida has claimed a data theft at SIA Medical Centre, an Australian medical group that runs nine clinics across Melbourne’s northwest, according to tracker listings logged on August 13.
The gang says it walked off with roughly 20,000 patient records, including names, dates of birth, Medicare numbers, clinical notes, insurance and workers compensation files, and full patient dossiers. It also claims to hold staff identity documents such as passports, driver’s licenses, police checks, and tax file declarations, plus plaintext credentials for clinical systems including Synapse imaging and the PRODA identity service.
SIA Medical was founded in 1993 by Dr Martin Sia and operates clinics in Box Hill, Burwood, Croydon, Essendon, Footscray, Moonee Ponds, Montrose, Mulgrave, and Berwick. Trackers at ransomware.live and RansomLook recorded the listing on August 13, the same day as the estimated attack date.
The practice has not publicly confirmed the claim, and leak site listings are frequently exaggerated or fabricated. Medicare numbers are Australia’s universal healthcare identifiers, and their exposure alongside plaintext clinical system credentials would make this a high-risk incident if the claim holds.
For Australian providers, the practical moves are to watch for phishing built around the claim, review any shared vendor relationships with SIA Medical, and treat unsolicited extortion email as high priority. Rhysida has a history of targeting healthcare and of leaking quickly when ransoms go unpaid, so staff credential reviews are a reasonable precaution.
