Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo Healthcare Retroactive Audits

Group: Dragonforce

Discovered by ransomware.live: 2025-11-26

Estimated attack date: 2025-11-26

Description:

22 171 128 medical record files, neatly packaged into 11 archives by hospital. The firm Healthcare Retroactive Audits, which was auditing the data for insurers, not only let the leak happen but also took no steps to stop the files from being published. When we approached NIH Information Security Program to discuss the issue, they said they weren’t interested in resolving it. We’re now open to talks with the affected organizations, insurers and the hospitals whose data were lost. These files are only a portion of the total breach, and we’re deciding whether to keep the release at this size or expand it.



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abuse godaddy.com
MX Records
  • smtp.healthcareaudits.net.
  • healthcareaudits-net.mail.protection.outlook.com.
TXT Records
  • v=spf1 include:_spf.healthcareaudits_net._d.easydmarc.pro -all
  • MS=ms43379038
  • v=verifydomain MS=7463936
Cloud / SaaS Services Detected
Microsoft 365

Leak Screenshot:

Leak Screenshot