Singing River Health System, a three-hospital community network on the Mississippi Gulf Coast, has confirmed that a December 2025 intrusion into its network exposed the personal and medical records of 53,888 patients. The Anubis ransomware gang has claimed credit for the attack, posting proof of stolen data, including what researchers describe as intimate images of surgeries and injuries, on its dark web leak site. The health system disclosed the official victim count to the U.S. Department of Health and Human Services' Office for Civil Rights last month.
What Happened
According to Singing River, attackers were inside its network from Dec. 19 to Dec. 21, 2025, before staff discovered the unauthorized access. The detection came a few days after the intruders had already established a foothold, after which the system deployed containment protocols and brought in a third-party cybersecurity firm to investigate.
By February 2026, the investigation confirmed that sensitive patient data had been accessed by the attackers. The health system notified known victims and offered complimentary credit monitoring, advising affected patients to watch their financial records for unusual activity. Singing River also stated it had since implemented security upgrades intended to prevent a similar incident.
Last week, researchers at Comparitech published a report revealing that Anubis, a cybercrime group with a track record of targeting healthcare organizations, had publicly claimed the breach on its own leak site.
What Was Taken
The stolen data set is broad and highly sensitive. Singing River confirmed the compromised records included contact information, Social Security numbers, dates of birth, government IDs, treatment details, diagnostic test results, medication lists, bank account information, health insurance numbers, and provider names.
Anubis claims to hold 293 GB of data spanning more than 1.2 million files. To substantiate the claim, the group posted samples to its leak site, including clinical imagery that Comparitech characterized as intimate images of surgeries and injuries. The combination of financial identifiers, medical history, and clinical photographs makes this a high-impact exposure for the affected patients.
Why It Matters
Healthcare remains one of the most heavily targeted sectors for ransomware, and Singing River illustrates why. The data taken supports nearly the full spectrum of follow-on fraud: Social Security numbers and dates of birth enable identity theft, bank account details enable financial fraud, and insurance numbers enable medical billing fraud. Unlike a payment card, this information cannot simply be reissued.
The publication of clinical imagery raises the stakes beyond financial harm into reputational and psychological harm for victims, a tactic increasingly used to pressure organizations into paying. A roughly two-day dwell time before detection also underscores how quickly attackers can locate and exfiltrate large volumes of data once inside a hospital network.
The Attack Technique
The initial access vector has not been publicly confirmed by Singing River or by Comparitech. What is notable is Anubis' own narrative: the gang publicly accused the health system of running lax security and systems that had received very little upgrade over time, framing the victim as an easy target.
While that claim should be treated as attacker messaging rather than verified fact, it aligns with a common pattern in healthcare breaches, where aging infrastructure, deferred patching, and limited segmentation give intruders room to move laterally and stage large exfiltration before defenders react.
What Organizations Should Do
- Prioritize patching and lifecycle management for internet-facing systems and core clinical infrastructure, closing the gaps that attackers like Anubis explicitly target.
- Deploy detection tuned for early-stage intrusion behavior, since a two to three day dwell time is enough to catch attackers before exfiltration if monitoring is in place.
- Segment clinical, administrative, and backup networks so that a single foothold cannot reach the full patient data set.
- Implement and alert on data loss prevention controls to flag the bulk movement of hundreds of gigabytes leaving the environment.
- Maintain tested, offline backups and a rehearsed incident response plan that includes legal, regulatory notification, and communications workflows.
- Treat medical imagery and clinical media as crown-jewel data with access controls and encryption commensurate with its sensitivity.
Sources: Anubis ransomware gang claims credit as Mississippi hospital reveals attack impacted 54K patients