Goshen Medical Center in North Carolina and Medical Associates of Brevard in Florida are notifying over 700,000 patients of data breaches attributed to the now-dormant BianLian ransomware group. Compromised data includes sensitive personal and health information, with both clinics offering affected individuals 12 months of complimentary credit and identity monitoring. The BianLian group has not claimed new victims since March 2025, and security experts suspect the group may have rebranded due to negative publicity.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
BankInfoSecurity and GovInfoSecurity reported that two clinics disclosed data breach notifications affecting a combined roughly 700,000 patients, with the incidents allegedly linked to the BianLian ransomware group. No earlier incident, attack, or remediation dates were provided in the reference content, so the disclosure date is inferred from publication.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.