The Anubis ransomware group has claimed responsibility for a cyber attack on Singing River Health System (SRHS), a Mississippi-based healthcare provider, compromising the sensitive personal information of more than 53,888 individuals. The group listed SRHS on its data leak site on June 4, 2026, alleging the theft of roughly 293 GB of data spanning more than 1.2 million files. The claim followed SRHS's own public disclosure of a major security incident traced back to unauthorized network access in late December 2025.
What Happened
According to SRHS, an unauthorized party gained access to its internal network and operated inside its systems between December 19 and December 21, 2025. The provider detected the intrusion, launched an investigation to determine the scope, and notified relevant law enforcement authorities.
On February 10, 2026, the investigation determined that the intruder had accessed SRHS files containing patient information. The Anubis ransomware group's public claim arrived shortly after SRHS posted its incident notice, with the actor listing the provider as a victim and publishing sample images to substantiate the breach. Anubis did not disclose any ransom amount or indicate whether SRHS had entered into negotiations.
What Was Taken
The exposed dataset is exceptionally sensitive, combining financial, identity, and clinical records. According to SRHS, the compromised information included:
- Names and contact information
- Social Security numbers
- Driver's license numbers
- Dates of birth
- Bank account information
- Health insurance information
- Provider names and internal patient identification numbers
- Dates of service, medication information, and treatment or diagnostic details
Anubis claims it exfiltrated approximately 293 GB of data totaling more than 1.2 million files. In its filing with the U.S. Department of Health and Human Services Office for Civil Rights, SRHS reported at least 53,888 affected individuals.
Why It Matters
This incident sits at the dangerous intersection of healthcare and double-extortion ransomware. The stolen data is a near-complete identity kit: Social Security numbers, dates of birth, and driver's license numbers enable identity theft, while bank account details support direct financial fraud. The inclusion of diagnoses, medications, and treatment history adds a layer of medical privacy exposure that can fuel targeted phishing, insurance fraud, and extortion of individuals.
The roughly seven-week gap between the December intrusion and the February confirmation that patient files were accessed underscores how long forensic analysis can take, leaving victims exposed before notification. Anubis's decision to publish sample images and post SRHS to its leak site is a pressure tactic designed to force payment, and it signals that the data is at real risk of broad criminal distribution regardless of whether a ransom is paid.
The Attack Technique
SRHS has not publicly detailed the initial access vector. What is confirmed is that the unauthorized party obtained access to the internal network and maintained it across a roughly two-day window, December 19 to December 21, 2025, during which patient files were accessed and, per Anubis, exfiltrated at scale.
The pattern is consistent with modern data-extortion ransomware operations: gain a foothold, move toward file shares and databases holding regulated data, stage and exfiltrate large volumes, then leverage a leak site to coerce payment. The reported 293 GB across 1.2 million files points to access to substantial repositories of patient records rather than a narrow, single-system compromise.
What Organizations Should Do
- Enforce phishing-resistant multifactor authentication on all remote access, VPN, and privileged accounts to close the most common initial access paths.
- Deploy and monitor endpoint detection and response (EDR) tooling to catch lateral movement and the bulk file access that precedes large-scale exfiltration.
- Implement egress monitoring and data loss prevention controls to flag abnormal outbound transfers, which can shorten dwell time before hundreds of gigabytes leave the network.
- Maintain segmented, tested, offline backups and a rehearsed incident response plan so recovery does not depend on attacker cooperation.
- Encrypt sensitive data at rest and tightly restrict access to repositories holding SSNs, financial, and clinical records on a least-privilege basis.
- For affected individuals, monitor credit reports, account and benefit statements, place fraud alerts or credit freezes, and report suspicious activity to law enforcement and the state attorney general.
Sources: Anubis group claims a ransomware attack on Singing River Health System