The Rhysida ransomware operation has intensified its focus on healthcare, with reporting and government guidance describing an expanding threat that has hit organizations across Western Europe, the Americas, and Australia. U.S. health-sector alerts and vendor research say the group has targeted education, government, manufacturing, technology, managed service providers, and increasingly healthcare and public health entities. Researchers have also linked Rhysida to tactics associated with the defunct Vice Society operation, while earlier incidents included the leak of stolen documents from the Chilean Army and suspected involvement in disruptive attacks on medical providers.
Security reporting says Rhysida commonly gains initial access through phishing and then uses tools such as Cobalt Strike and PowerShell to disable defenses, delete shadow copies, alter RDP settings, and deploy ransomware. In a newly reported healthcare case, SIA Medical Centre was listed as a victim, with the attackers claiming theft of roughly 20,000 patient medical records along with staff identity documents, plaintext credentials, HR files, and legal and financial records. The allegedly exposed data included names, dates of birth, Medicare numbers, clinical notes, insurance files, passports, driver’s licenses, and login credentials, underscoring the group’s dual risk of operational disruption and large-scale sensitive data exposure in the health sector.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
A ransomware-related data breach affecting SIA Medical Centre was discovered on August 13, 2026, and attributed to Rhysida. The attackers claimed to hold about 20,000 patient medical records, staff identity documents, plaintext credentials, HR records, and legal and financial files.
BleepingComputer reported increased scrutiny of Rhysida amid a wave of attacks on healthcare organizations, including a healthcare victim in Australia listed on the group's leak site with a one-week payment deadline. The article also cited HHS and vendor reporting that the group's activity had expanded significantly.
Trend Micro reported that Rhysida commonly gains initial access through phishing and uses Cobalt Strike and PowerShell scripts to terminate antivirus processes, delete shadow copies, and modify RDP settings before deploying ransomware. The report also assessed that reliance on external scripts suggested the locker was still under active development.
Cisco Talos reported on Rhysida's ransomware, describing its use of a 4096-bit RSA key with ChaCha20 encryption and noting exclusions for certain directories and file types. The publication documented technical characteristics of the latest locker variant.
In June 2023, Rhysida drew attention after publishing documents stolen from the Chilean Army on its data leak site. The leak was cited as an early notable incident tied to the group.
BleepingComputer reported that sources linked Rhysida to a recent cyberattack on Prospect Medical Holdings that caused a system-wide outage affecting 17 hospitals and 166 clinics in the United States. At the time, neither Rhysida had publicly claimed the attack nor Prospect confirmed the attribution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
hookphish.com
Open sourcebleepingcomputer.com
Open sourcetrendmicro.com
Open sourceblog.talosintelligence.com
Open sourceresearch.checkpoint.com
Open sourcehhs.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.