Critical Unverified

General Santos Doctors Hospital Ransomware Claim by Rhysida (Sep 2026)

By Yazoul AI · automated

Unverified dark web claim. This report is based on a post observed on a dark web forum. Yazoul Security has not independently verified the authenticity of this claim.

Leak Site Screenshot

Leak site post claiming General Santos Doctors Hospital data breach

Screenshot captured at time of discovery. Image blurred to protect victim PII.

Leak site post claiming General Santos Doctors Hospital data breach - full size

Claim Summary

On or around September 10, 2026, the Rhysida ransomware group allegedly listed General Santos Doctors Hospital, a healthcare provider in the Philippines, on its dark web leak site. According to the threat actor, the group claims to have exfiltrated approximately 3,502,636 files totaling roughly 2.44 TB of data.

The claim has not been independently verified by Yazoul Security, and no confirmation has been issued by General Santos Doctors Hospital. Ransomware operators frequently publish inflated or partially fabricated claims to pressure victims into paying. This report should be treated as an unverified assertion, not a confirmed breach.

Threat Actor Profile

rhysida is a ransomware operation that emerged in mid-2023 and is known for targeting healthcare, education, government, and manufacturing sectors. The group typically employs double extortion - encrypting victim systems while exfiltrating data to coerce payment. Rhysida has historically demanded ransoms payable in Bitcoin and has been observed auctioning stolen data when victims decline to pay.

Public reporting has linked Rhysida to the use of off-the-shelf tooling and living-off-the-land techniques, though specific tooling details for this alleged incident are not available. No public research references were provided with the leak site data, and the group’s total victim count remains unclear. As with all ransomware claims, the accuracy of the group’s assertions should be treated with skepticism.

Alleged Data Exposure

The threat actor claims the purported dataset includes highly sensitive categories:

  • Patient data (PHI): allegedly name-tagged scans across department shares, including surgical pathology, hemodialysis charts, admission records, cancer-center dossiers with PhilHealth IDs, lab quotations with cancer-marker tests and birth dates, PhilHealth claims monitoring, and neonatal (NICU) data.
  • Staff and professional records: an accredited physicians register with cell numbers, PRC licenses, and PhilHealth IDs; named payroll workbooks; HR dossiers; passport scans; and drug-test files.
  • Financial and governance records: audited financial statements allegedly signed by executives with BIR stamps, balance sheets, bank account details across multiple institutions, internal audit memos, SEC stockholders’ minutes, and payroll bank-upload batches.
  • Leadership personal data: personal cell numbers of the president, hospital administrator, and board members.

Yazoul Security has not reviewed any of this material and cannot confirm its existence, authenticity, or completeness.

Potential Impact

If the claim is accurate, the exposure of patient health information, physician credentials, and financial records could constitute a significant privacy and regulatory event under Philippine data protection law. Affected individuals could face identity theft, medical fraud, or targeted phishing. The hospital could face regulatory scrutiny, litigation, and reputational harm.

However, the mere presence of a leak site listing does not confirm that data was actually stolen or that it is genuine. Some groups recycle or fabricate samples.

What to Watch For

  • Official statements from General Santos Doctors Hospital or Philippine regulators.
  • Notification letters to patients, physicians, or staff.
  • Evidence of data being auctioned or released, which would raise confidence in the claim.
  • Indicators of Rhysida tooling or persistence mechanisms in healthcare networks.

Organizations in the healthcare sector should review detection coverage for common Rhysida tactics. Where available, YARA rules targeting Rhysida payloads and exfiltration utilities can support hunting. See our advisory resources for detection guidance.

Disclaimer

This report is based solely on an unverified claim published by the Rhysida ransomware group. Yazoul Security has not independently confirmed the breach, the data’s existence, or its contents. Ransomware groups routinely exaggerate claims. Nothing here should be treated as fact. Affected parties should await official confirmation.

Share:

Never miss a threat intelligence alert

Get real-time security alerts delivered to your preferred platform.

Related Claims

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.