Sunflower Medical Group, a healthcare provider serving Kansas and Missouri, has agreed to pay $1.2 million to settle a class action lawsuit following a ransomware attack attributed to the Rhysida cybercrime gang. The breach compromised sensitive data of nearly 256,000 individuals, with Rhysida claiming responsibility and listing Sunflower Medical as a victim on its leak site. Under the preliminary court-approved settlement, affected individuals can claim a one-time cash payment or submit receipts for out-of-pocket losses, while plaintiff attorneys have requested half of the settlement for fees and expenses. Sunflower Medical has also committed to providing a confidential declaration on additional cybersecurity safeguards implemented to mitigate future breaches.
The final approval hearing for the settlement is scheduled in Missouri state court. The Rhysida group, known for targeting healthcare organizations, claims to have stolen an SQL database from Sunflower Medical. The incident highlights ongoing risks to healthcare data security and the legal and financial consequences organizations face following ransomware attacks. No evidence from the provided references suggests that the breach involved other medical groups or was part of a broader coordinated attack beyond Sunflower Medical Group.

TTPs, infrastructure, and targeting history in one profile.
6 events from the most recent confirmed update back to the earliest known activity.
A final approval hearing for the proposed settlement was scheduled in Missouri state court for March 6. The lawsuit alleged negligence, breach of fiduciary duty, and violations of state laws.
By December 2025, Sunflower Medical agreed to pay $1.2 million to settle a class action lawsuit over the breach. The settlement also included victim compensation options and commitments to additional cybersecurity safeguards.
As of December 2025, the Rhysida gang still listed Sunflower Medical Group as a victim on its leak site. This indicated the stolen data remained part of the group's public extortion pressure campaign.
In March 2025, Sunflower Medical notified federal and state regulators about the incident. Reported compromised data included driver's license images, health insurance cards, and Social Security numbers.
Sunflower Medical discovered the breach in January 2025 after the December 2024 attack. The incident ultimately affected nearly 256,000 individuals.
In December 2024, Sunflower Medical Group suffered a ransomware attack later attributed to the Rhysida cybercrime gang. The attackers allegedly stole more than 3 terabytes of data from the healthcare provider.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.