Healthdaq, a Dublin-based recruitment platform used by Northern Ireland health trusts and other public health bodies, disclosed unauthorized access to its systems after attackers linked to the XP95 extortion group claimed to have stolen nearly half a million files. Reported exposed data includes names, contact details, CVs, qualifications, passport copies, other government-issued identification, criminal background checks, vaccine records, forms, and in some cases health information. Healthdaq said it detected the breach on 30 March, contained the incident, and notified regulators and law enforcement, including the Garda National Cyber Crime Bureau, while the UK Information Commissioner's Office said it is assessing the company’s report.
The incident prompted heightened alerts across Northern Ireland health trusts because of the volume and sensitivity of the compromised records and the risk of identity theft, fraud, and misuse of personal information. Reporting indicates Healthdaq received a ransom demand, and threat intelligence describes XP95 as a newly observed actor using a pure data theft and extortion model rather than file-encrypting ransomware; its first publicly identified victim was Eholo Health, a Spanish mental health SaaS provider serving psychologists in Spain and Andorra. The breach also underscored broader pressure on healthcare technology suppliers after a separate attack on Dutch EPD vendor ChipSoft disrupted hospital services and triggered parliamentary scrutiny over sector dependence on a small number of critical vendors.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
Lawmakers from D66 asked Health Minister Hermans to explain the impact of the ChipSoft incident on healthcare continuity, whether patient data was stolen, and whether cybersecurity requirements for critical healthcare IT suppliers are adequate. The attack also prompted at least 23 data leak notifications to the Dutch Data Protection Authority.
A ransomware attack on ChipSoft, a major Dutch electronic patient dossier software provider, disrupted healthcare operations and led several hospitals to take patient portals offline. ChipSoft reportedly disconnected multiple platforms and began restoring services using new keys.
Following reporting on the Healthdaq breach and XP95's claims, Northern Ireland health trusts were placed on high alert because the recruitment platform was used by the trusts. The incident raised concerns over identity theft, fraud, and exposure of sensitive applicant data.
The UK Information Commissioner's Office said it had received a report from Healthdaq Limited and was assessing the information provided. This confirmed regulatory notification following the breach disclosure.
XP95 claimed responsibility for the Healthdaq intrusion, saying it stole nearly half a million files. Reported exposed data included names, contact details, CVs, qualifications, passport and other government ID copies, criminal background checks, vaccine records, and in some cases health information.
Healthdaq said it became aware of unauthorized access to its systems on 2026-03-30 and took steps to contain the incident. The company later reported the matter to regulators and law enforcement, including the Garda National Cyber Crime Bureau.
Threat intelligence reporting says XP95, a data-theft-and-extortion actor, was first observed on 2026-03-04. Its first known victim was Eholo Health, a Spanish mental health SaaS platform serving psychologists in Spain and Andorra.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
cyberwarzone.com
Open sourcesiliconrepublic.com
Open sourceirishtimes.com
Open sourcebbc.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.