Cyber & AI intelligence
Wasteland.
Briefs indexed2862
Issues29
Published Mondays07:30 CT
█ Ransomware WELLDYNE-RANSOMWAR 2026-09-24

WellDyne: Ransomware Group Claims Data Theft From Pharmacy Benefit Manager

"WellDyne is a pharmacy benefit manager (PBM) based in Lakeland, Florida. It has disclosed a data breach after a ransomware group calling itself "payoutsking" claimed to have stolen internal files. The breach was…"

WellDyne is a pharmacy benefit manager (PBM) based in Lakeland, Florida. It has disclosed a data breach after a ransomware group calling itself "payoutsking" claimed to have stolen internal files. The breach was detected in June 2026. According to Class Action U, WellDyne reported a hacking/IT incident involving a network server to the U.S. Department of Health and Human Services Office for Civil Rights (HHS OCR), and the reported impact includes at least 500 Florida residents. We have no statement from WellDyne itself and no regulator filing. Every detail about the breach in this brief comes from one secondary source, and we attribute it that way. WellDyne has not published a national victim count, and none of our sources gives one.

What Happened

Class Action U reports this timeline:

Class Action U gives no exact date for the HHS OCR filing. We could not find WellDyne's notification letter, a Florida Attorney General entry, or any statement from the company about when the intrusion began or how long the attacker had access.

The 500-resident figure is a floor, not a total. Florida requires breaches affecting 500 or more state residents to be reported to the Attorney General, so "at least 500" probably marks that reporting threshold rather than a full count. Class Action U makes the same point: the number of people affected nationwide, across all the plans and employers WellDyne serves, could be considerably higher. That is a reasonable inference, but it is not confirmed.

About the victim: WellDyne was founded in 1990 and has offices in Lakeland, Florida and Centennial, Colorado. It runs PBM, specialty pharmacy, mail-order and central-fill services for health plans, employers and government programs. Health Law Alliance reports that it is an independent PBM, owned by the Carlyle Group since 2017, with no health-plan or drug-manufacturer parent. Estimates of its size disagree. A LinkedIn-derived company profile lists 200 to 300 employees and $30M to $40M in revenue. A job-board listing puts headcount at 501 to 1,000. Neither is authoritative.

What Was Taken

The affected data categories have not been disclosed. Class Action U says WellDyne has not published a list of them. It notes that PBM records typically include names, contact details, insurance information and prescription history, but that is a general description of the industry and not a finding about this breach.

What WellDyne's own staff describe gives a sense of what its systems may hold. A long-tenured employee's LinkedIn profile says the company's Credit Card Security Team adds payment card details to patient accounts and attaches them to pending mail-order prescriptions. Nothing in the sources says payment data was accessed. Still, WellDyne's environment likely holds protected health information, insurance eligibility data and payment information together.

The leak site claim says only "internal files." We have not seen any independent confirmation of how much data was taken or whether any of it has been published.

Why It Matters

The Attack Technique

The attack technique is unknown. The HHS OCR category Class Action U reports ("hacking/IT incident" on a "network server") is a standard classification and says nothing about how the attacker got in. Nothing has been published about the initial access vector, the ransomware variant, whether systems were encrypted, or whether a ransom was paid.

payoutsking's behaviour matches the double-extortion model: steal the data, then post the victim on a leak site to pressure them into paying. We have no reliable reporting on this group's tools or usual entry points, so we will not guess. We will update this brief if WellDyne's notification letters or a regulator filing add technical detail.

What Organizations Should Do

  1. Plan sponsors using WellDyne: Request written confirmation from WellDyne of whether your members are affected, which data fields were involved and the notification timeline. Check your business associate agreement for breach notification obligations and deadlines.
  2. Map your third-party data exposure: List every PBM, claims processor and pharmacy vendor that holds member PHI, and check that each keeps only the data it needs.
  3. Watch for follow-on fraud: Brief member services and fraud teams to expect breach-themed phishing and medical identity theft attempts. Advise members to review their explanation-of-benefits statements for prescriptions they did not fill.
  4. Harden server-side exposure: Ransomware crews that exfiltrate data usually go after internet-facing servers, VPNs and remote access tools. Patch those systems, require phishing-resistant MFA, and alert on unusually large outbound transfers.
  5. Keep payment data separate from clinical data: If your organisation stores card data alongside PHI, as WellDyne's mail-order operation appears to, keep them in separate network segments with separate access controls. One compromised server should not expose both.
  6. Watch for leak site activity: Add your vendors to your dark-web monitoring so you hear about a leak site listing before a class action firm does.

Sources: WellDyne Data Breach Lawsuit - Class Action U | PharmaStrategies, LLC v. WellDyneRX, LLC, 23-01041 | WellDyne Pharmacy Audit: Response Strategy | Karon Carter | Account Manager at WellDyne - United States Remote | McKesson discloses breach after ShinyHunters claims patient data th... | WellPoint Texas Data Breach: Edelson Lechtzin LLP Launches Investig... | WellPoint Texas, Inc. Data Breach – Investigated by Federman & Sher...