Dark Web Intelligence Summary
A credential set attributed to a healthcare sector breach is circulating on a closed-access forum. Records include email, plaintext passwords (suggesting an older breach), and patient reference IDs.
Tor Listing Proof & Evidence
● Verified Tor Capture
http://breached672x3a9m0v2.onion/thread/hc-leak-890k
Source: BreachedForums (Tor Network)
Actor: GhostIntel_v2
Sector: Healthcare & Lifesciences
Listing Price: $3,800 USD (Monero)
Redacted Sample Excerpts:
user_id: 884920 | email: m.*****@healthmed-care.com | hash: 5e884898da28047151d0e56f8dc6292773603d0d6aabbdd62a11ef721d1542d8 | pat_ref: PAT-2025-9921
user_id: 884921 | email: s.*****@regional-hospital.org | hash: 8c6976e5b5410415bde908bd4dee15dfb167a9c873fc4bb8a81f6f2ab448a918 | pat_ref: PAT-2025-9922
user_id: 884922 | email: dr.*****@medcenter-east.com | hash: [REDACTED_SALT_BCRYPT] | pat_ref: PAT-2025-9925

Technical Analysis & Assessment

A massive dataset containing 890,000 credentials and patient metadata records has been listed on an underground closed-access forum.

Threat Analysis & Findings

The dataset appears to be a composite dump exfiltrated from legacy patient portal backend systems. Analysis of sample records indicates a mixture of unsalted MD5 hashes and legacy bcrypt hashes.

Key Observations

  • Primary affected domains belong to regional hospital networks across North America and Europe.
  • The thread author claims the data was harvested via SQL injection in a legacy billing API.
  • Over 45,000 corporate staff emails (physicians, nurses, administrative staff) are present in the list.

Recommended Mitigation Actions

  • Force immediate password resets for all active portal accounts matching affected domain suffixes.
  • Audit external-facing API endpoints for SQL injection vulnerabilities.
  • Enable mandatory Multi-Factor Authentication (MFA) across all staff and patient portals.
TAGS:#credential-set#healthcare-&-lifesciences#intel#exposure