Singing River Health System, a three-hospital community network in Mississippi, has confirmed that a December 2025 intrusion exposed the records of 53,888 patients. The Anubis ransomware gang has publicly claimed responsibility, posting proof of the theft on its dark web leak site, including what researchers describe as intimate clinical imagery.
What Happened
According to Singing River, attackers were inside its network from Dec. 19 to Dec. 21, 2025, before staff discovered the unauthorized access and deployed containment protocols. The intrusion was only caught a few days after the criminals had already established a foothold. The health system engaged a third-party cybersecurity firm to investigate and, in February 2026, confirmed that sensitive patient data had been accessed. Last month it filed official breach figures with the U.S. Department of Health and Human Services Office for Civil Rights, formalizing the 53,888-patient count. Researchers at Comparitech reported that Anubis, a cybercrime group with a track record of targeting healthcare entities, claimed credit on its own leak site.
What Was Taken
The stolen data is broad and deeply sensitive. Singing River confirmed exposure of contact information, Social Security numbers, dates of birth, government IDs, treatment details, diagnostic test results, medication lists, bank account information, health insurance numbers and provider names. Anubis claims to hold 293 GB of data spanning more than 1.2 million files. To prove its access, the gang posted samples that Comparitech characterized as intimate images of surgeries and injuries, a disclosure that goes well beyond typical financial identity exposure and into acute patient privacy harm.
Why It Matters
This incident reflects the continued targeting of community and regional health systems, which often operate with constrained security budgets relative to large urban networks. The combination of financial identifiers, insurance numbers and clinical records makes affected patients vulnerable to both fraud and extortion. The publication of surgical and injury imagery raises the stakes from data theft to reputational and psychological harm against individuals. Anubis publicly disputed the adequacy of Singing River's defenses, framing the breach as the result of neglected infrastructure, a narrative that mirrors a broader pattern of ransomware crews shaming under-resourced healthcare victims to pressure payment.
The Attack Technique
The gang asserts it gained access by exploiting lax security, specifically systems it claims had received very little upgrade over an extended period. While Singing River has not detailed the initial access vector, the two-day dwell time before detection points to gaps in network monitoring and alerting. Unpatched or end-of-life systems are a recurring entry point in healthcare breaches, and Anubis's framing aligns with that hypothesis. The health system has since stated it implemented security upgrades following the incident, an implicit acknowledgment that its prior posture left exploitable gaps.
What Organizations Should Do
- Inventory and patch aggressively. Identify legacy and end-of-life systems, prioritize patching internet-facing and clinical infrastructure, and decommission what cannot be maintained.
- Shorten detection time. Deploy endpoint detection and response and network monitoring tuned to flag lateral movement and data staging within hours, not days.
- Segment networks. Isolate clinical, administrative and imaging systems so a single compromise cannot reach the full patient data estate.
- Protect and monitor sensitive data stores. Encrypt records at rest, restrict access to clinical imagery, and alert on bulk data access or exfiltration patterns.
- Test incident response. Run tabletop exercises that assume attacker dwell time and rehearse containment, notification and recovery workflows.
- Prepare for extortion scenarios. Establish legal, communications and law enforcement playbooks for cases where stolen data, including imagery, is published rather than merely encrypted.
Sources: Anubis ransomware gang claims credit as Mississippi hospital reveals attack impacted 54K patients