SYS::ONLINE
Wasteland.
Briefs1263
Issues20
SinceFeb 2026
LIVE
█ Ransomware RSUI-NOVA-RANSOMWA 2026-07-21

Rumah Sakit Universitas Indonesia (RSUI): Nova Ransomware Attack

"Rumah Sakit Universitas Indonesia (RSUI), the teaching hospital of the University of Indonesia, has been listed as a victim on the data-leak infrastructure of the 'nova' ransomware group. According to claims published…"

Rumah Sakit Universitas Indonesia (RSUI), the teaching hospital of the University of Indonesia, has been listed as a victim on the data-leak infrastructure of the 'nova' ransomware group. According to claims published on 2026-07-20, the actor infiltrated RSUI systems, placed the hospital's medical data at risk, and claims to have exfiltrated files. Nova states it provided a proof tree and data samples to RSUI's support department as evidence of the intrusion. As of publication, the hospital has issued no official statement confirming or denying the incident.

What Happened

RSUI reported ransomware activity affecting medical data stored on impacted drives after the nova threat actor gained access to its environment. The nova group named RSUI on its Tor-based leak site, a common tactic in double-extortion operations where victims are publicly pressured to pay by threatening to release stolen data.

The listing was discovered on 2026-07-20 at 15:04 UTC, roughly one minute after it was published to the leak portal at 15:03 UTC. Nova claims it made contact with RSUI's support department and supplied a directory tree along with samples drawn from the allegedly stolen data. This tree-and-sample approach is a signature pressure technique: it demonstrates the actor holds real files while withholding the full trove pending negotiation.

At this stage, the claims originate entirely from the threat actor. The severity, scope, and volume of the compromise cannot be independently verified from the leak listing alone.

What Was Taken

Nova asserts it exfiltrated medical data from RSUI drives. As a full-service teaching hospital delivering advanced clinical care, education, and research, RSUI processes some of the most sensitive categories of personal information that exist:

The actor has published a proof tree and file samples rather than a complete dump, meaning the exact record count and total data volume remain unconfirmed. Even partial exposure of protected health information carries severe consequences for affected individuals, from medical identity theft to targeted fraud.

Why It Matters

Healthcare remains one of the most heavily targeted sectors for ransomware because the combination of life-critical operations and irreplaceable patient data maximizes pressure to pay. A teaching hospital compounds the risk: it holds not only patient records but also academic research and the personal data of medical students and faculty.

The exposure of patient medical data threatens patient privacy, regulatory compliance under Indonesian data protection law, and the trust patients place in the institution. Attacks on hospitals can also degrade or halt clinical services, directly endangering patient safety when systems supporting diagnostics, scheduling, or care delivery are encrypted or taken offline.

For defenders across the region, the RSUI listing is another data point confirming that Indonesian healthcare providers are squarely within the targeting scope of active extortion crews like nova.

The Attack Technique

The leak listing does not disclose the initial access vector, and nova has not published technical details of the intrusion. The group's stated workflow, infiltrating systems, exfiltrating data, and then contacting the victim's support department with a proof tree and samples, aligns with standard double-extortion ransomware operations.

While the specific entry point at RSUI is unknown, ransomware groups targeting healthcare commonly rely on:

Absent confirmation from RSUI or investigators, these represent probable rather than confirmed vectors for this specific case.

What Organizations Should Do

Healthcare providers, particularly those in the region, should treat this listing as a prompt to harden defenses against double-extortion ransomware:

  1. Enforce phishing-resistant multi-factor authentication on all remote access, VPN, and administrative accounts to blunt credential-based intrusions.
  2. Patch internet-facing systems, VPN gateways, and email infrastructure on an aggressive schedule, prioritizing actively exploited vulnerabilities.
  3. Maintain offline, immutable backups of clinical and administrative systems and routinely test full restoration to ensure recovery without paying a ransom.
  4. Deploy network segmentation to isolate medical record servers and clinical systems, limiting an intruder's ability to move laterally and mass-exfiltrate data.
  5. Monitor for anomalous outbound data transfers and unusual access to bulk medical records, which can catch exfiltration before public extortion begins.
  6. Rehearse an incident response and communications plan so that legal, regulatory notification, and patient-notification obligations can be met quickly if data is confirmed stolen.

Sources: Ransom! Rumah Sakit Universitas Indonesia (RSUI) (JUL-2026)