Dark Web Intelligence Summary
A credential set attributed to a healthcare sector breach is circulating on a closed-access forum. Records include email, plaintext passwords (suggesting an older breach), and patient reference IDs.Tor Listing Proof & Evidence
● Verified Tor CaptureSource: BreachedForums (Tor Network)
Actor: GhostIntel_v2
Sector: Healthcare & Lifesciences
Listing Price: $3,800 USD (Monero)
Redacted Sample Excerpts:
user_id: 884920 | email: m.*****@healthmed-care.com | hash: 5e884898da28047151d0e56f8dc6292773603d0d6aabbdd62a11ef721d1542d8 | pat_ref: PAT-2025-9921 user_id: 884921 | email: s.*****@regional-hospital.org | hash: 8c6976e5b5410415bde908bd4dee15dfb167a9c873fc4bb8a81f6f2ab448a918 | pat_ref: PAT-2025-9922 user_id: 884922 | email: dr.*****@medcenter-east.com | hash: [REDACTED_SALT_BCRYPT] | pat_ref: PAT-2025-9925
Technical Analysis & Assessment
A massive dataset containing 890,000 credentials and patient metadata records has been listed on an underground closed-access forum.
Threat Analysis & Findings
The dataset appears to be a composite dump exfiltrated from legacy patient portal backend systems. Analysis of sample records indicates a mixture of unsalted MD5 hashes and legacy bcrypt hashes.
Key Observations
- Primary affected domains belong to regional hospital networks across North America and Europe.
- The thread author claims the data was harvested via SQL injection in a legacy billing API.
- Over 45,000 corporate staff emails (physicians, nurses, administrative staff) are present in the list.
Recommended Mitigation Actions
- Force immediate password resets for all active portal accounts matching affected domain suffixes.
- Audit external-facing API endpoints for SQL injection vulnerabilities.
- Enable mandatory Multi-Factor Authentication (MFA) across all staff and patient portals.
TAGS:#credential-set#healthcare-&-lifesciences#intel#exposure