Cyber & AI intelligence
Wasteland.
Briefs indexed2597
Issues28
Published Mondays07:30 CT
█ Ransomware GENERAL-SANTOS-DOC 2026-09-12

General Santos Doctors Hospital: Rhysida Extortion Listing and Disputed Data Leak

"The Rhysida ransomware group has listed General Santos Doctors Hospital (GSDH) in the Philippines on its dark web leak site, claiming to hold 3,502,636 files totalling roughly 2.44 TB of hospital data including patient…"

The Rhysida ransomware group has listed General Santos Doctors Hospital (GSDH) in the Philippines on its dark web leak site, claiming to hold 3,502,636 files totalling roughly 2.44 TB of hospital data including patient Protected Health Information, staff identity documents and corporate financial records. The hospital disputes the claim. In a public advisory dated September 11, 2026, GSDH said its Management Information Systems team found "no indicators of unauthorized access, system compromise, ransomware activity or data exfiltration" at that point in its assessment, as reported by The Mindanao Sentinel. Accounts also differ on the status of the data itself: QPulse, citing the Ransomware.live tracker, describes the material as published, while the Sentinel describes an active extortion listing with a seven-day deadline, an 8 BTC demand and a threat to sell rather than a completed dump. Both available reports agree on the volume figures, and no source consulted for this brief is a regulator filing or a national CERT advisory, so the underlying intrusion remains unverified.

What Happened

Rhysida added GSDH to its victim portal in early September 2026, publishing a file inventory as proof of access. Per the Sentinel's account of the listing, the group gave the hospital seven days to respond, demanded 8 Bitcoin, and offered the dataset to a single exclusive buyer rather than reselling it repeatedly, a pitch Rhysida has used before to raise pressure on victims who stall.

GSDH's September 11 advisory acknowledged that it had received reports of an alleged breach and said MIS staff immediately began assessing and securing its information systems. The hospital said it is continuing to monitor, investigate and validate, and that it will comply with notification law if an incident is eventually confirmed. That is a narrower statement than a denial: an initial assessment finding no indicators is a point-in-time result, not a closed investigation, and Rhysida's business model depends on exfiltration that victims frequently fail to detect on first pass.

Neither available source establishes a breach date or an initial access vector, and neither reports contact between the hospital and the group. The framing that GSDH refused to pay is not supported by the sourcing here; what is documented is a demand, a deadline and a hospital that has not confirmed the incident.

What Was Taken

Treat the following as Rhysida's claims about the contents of its listing, reported by QPulse and the Sentinel, not as an independently verified inventory.

On patients: surgical pathology scans, hemodialysis charts, admission records, cancer-centre dossiers containing PhilHealth IDs, and neonatal intensive care unit data. The NICU and oncology material is the most damaging category in the set, because it ties named minors and cancer patients to specific diagnoses.

On staff and clinicians: physician registers with PRC licence numbers and PhilHealth IDs, payroll workbooks, HR dossiers and passport scans.

On the business: audited financial statements, balance sheets, bank account details spanning six banks, internal-audit memos covering cashier discrepancies, SEC stockholders' minutes, and direct contact details for the president, administrator and board members.

Volume is reported consistently at approximately 2.44 TB across about 3.5 million files, with the Sentinel giving the precise listing figure of 3,502,636 files. QPulse additionally reports staff credentials in the set; that detail appears in only one source and should be carried as a claim rather than a finding.

Why It Matters

The combination here is worse than a generic PHI dump. PhilHealth identifiers plus passport scans plus bank details give fraud operators a complete identity kit for both patients and employees, and the audited financials, audit memos and named-executive contact data are exactly what a follow-on extortion or business email compromise crew would want. Leadership contact details in a leaked set routinely become the input to direct pressure campaigns against executives and board members.

The listing also fits an established Rhysida pattern rather than standing alone. Wikipedia's tracking of the group records attacks on the Chilean army, the 2023 British Library intrusion, Insomniac Games, Prospect Medical Holdings, the City of Columbus, Seattle-Tacoma International Airport, the Maryland Department of Transportation, Stelia Aerospace and the Berlin state administration. CISA, the FBI and MS-ISAC issued a joint advisory on Rhysida in November 2023 and characterised it as striking targets of opportunity across education, healthcare, manufacturing, IT and government, with reported overlaps with Vice Society.

Two concurrent cases show the operating tempo. Security Affairs reported that Rhysida claimed Berlin's state administration on August 28, 2026, asserting 5.79 TB across roughly 1.44 million files with personal data on 12,076 individuals, including plaintext credentials and material touching classified handling and water-supply vulnerability analyses, with Berlin officials refusing to pay weeks before a September 20 state election. Separately, trackers list a healthcare provider identified as SIA Medical: Darkfield records an August 14, 2026 listing with 3 TB and roughly 20,000 patient records and places the victim in Australia, while cyberthreatintelligence.net dates disclosure to August 13 and places it in Latvia. The same trackers disagree on Rhysida's cumulative victim count, quoting both 200 and 273 victims since mid-2023. These discrepancies are a standing reminder that leak-site aggregators are useful for tempo and targeting, not for precise facts.

Country context sharpens the stakes. World Ngayon, citing CYFIRMA's Philippines threat landscape reporting for 2025 to 2026, describes healthcare as the most targeted sector in the Philippines, driven by unsupported operating systems, weak access control and rapid IoMT growth, with the 2023 Medusa attack on PhilHealth that exposed data on more than 42 million Filipinos as the reference point. On the scale question, the Aesto Health incident reported in September 2026 by CyberInk Times, involving ePHI for 9,540,683 individuals after unauthorised access to AWS infrastructure in December 2025, shows how far a single healthcare data custodian's exposure can reach.

The Attack Technique

No source identifies how GSDH was accessed, if it was. What is documented is Rhysida's general tradecraft. Per cyberthreatintelligence.net's profile, the group emerged in May 2023, operates as ransomware-as-a-service, gains initial access primarily through phishing (MITRE T1566), uses Cobalt Strike for post-compromise operations, drops PDF ransom notes in affected folders directing victims to a Tor portal, takes payment in Bitcoin, and appends a .ryshida extension to encrypted files. The CISA/FBI/MS-ISAC advisory remains the authoritative technical reference for detection content.

Worth noting for defenders: in both the Berlin and SIA Medical listings, Rhysida claimed plaintext credentials for production systems, including imaging and payment platforms. Credential stores sitting unencrypted on reachable file shares are a recurring theme in this group's claimed hauls, and they convert a single data theft into durable access across an estate.

What Organizations Should Do

1. Hunt before you declare. An initial assessment that finds no indicators is a starting point, not a conclusion. Hunt specifically for mass file reads, archiving utilities, anomalous outbound volume and cloud or FTP egress in the 30 to 90 days preceding the listing. A 2.44 TB exfiltration leaves traffic evidence even when no encryption ever fires, and the absence of ransomware artifacts says nothing about exfiltration.

2. Hunt for Rhysida-specific artifacts. Work from the CISA/FBI/MS-ISAC advisory: .ryshida extensions, PDF ransom notes dropped into shares, Cobalt Strike beacon traffic, and unexpected remote-access tooling. Check whether telemetry retention even covers the relevant window first.

3. Eliminate plaintext credential stores. Sweep file shares, scripts, scheduled tasks and wikis for hardcoded credentials to imaging systems, payment platforms and administrative accounts, move them into a managed secrets vault, and rotate anything found. Assume that anything discovered has already been read.

4. Harden the phishing-to-hands-on-keyboard path. Phishing is the documented entry point for this group. Enforce phishing-resistant MFA on all external access including VPN and remote desktop, and make sure identity alerting treats a successful login from an anomalous location as an incident rather than a log entry.

5. Segment clinical and corporate data, and protect the high-harm categories. Neonatal, oncology and pathology records, along with HR passport and payroll data, should sit behind separate access controls with their own audit trails. A single traversable share is how 3.5 million files become one listing.

6. Prepare the regulatory and patient-notification track in parallel. Philippine organisations should align response with Data Privacy Act notification duties to the National Privacy Commission and affected individuals, on the assumption that verification may take days while the extortion clock runs. Pre-drafted notification templates and a designated external counsel contact remove the worst delays.

7. Treat offline, tested backups as the recovery floor. Immutable or offline copies of clinical systems, with restoration actually rehearsed under a paper-charts scenario, are what decide whether an encryption event becomes a patient safety event.

Sources: Rhysida Ransomware Group Publishes Stolen Data from General Santos... | Rhysida Ransomware Group Targets Berlin Government Ahead of Vote | Rhysida Claims 2.44-TB Data Theft From General Santos Doctors ... | Philippine Healthcare Ransomware: Proven Hospital Defense Guide 2026 | Rhysida (hacker group) | SIA Medical data breach — Rhysida ransomware attack (2026) · Darkfield | SIA Medical Centre Ransomware Attack by Rhysida (2026) Cyber Threa... | Aesto Health Breach Hits 9.5M Patients, 2026's Second-Largest