← Blog

Mobilemed Claim: 35M Patient Records Alleged

Share on X

Unverified claim — July 10–11, 2026: Threat-intelligence accounts flagged an underground-forum post alleging a catastrophic breach of Mobilemed, one of Brazil's largest cloud PACS (Picture Archiving and Communication System) vendors. The actor claims 23.5 TB and 35 million patient PII records—numbers that would dwarf most 2026 healthcare leaks if validated. Mobilemed had not confirmed any matching incident at indexing time.

What threat actors claim

Dark Web Informer reported July 10, 2026 that a forum actor claimed to have breached Mobilemed, a Brazilian health-technology company whose platform stores and routes medical imaging for radiologists, hospitals, and diagnostic centers. The listing alleges:

  • 52.2 million files totaling 23.5 TB
  • 35 million patient PII records
  • 17,176,370 personal files
  • 67,493 account PII records
  • Sensitive patient information and internal credentials

The actor demanded a $1.5 million ransom with an August 1, 2026 payment deadline and threatened to sell the data if unpaid. Intel and Breaches echoed the same figures July 11, describing Mobilemed as a cloud PACS platform used by hospitals and diagnostic imaging centers nationwide.

What Mobilemed is

Mobilemed markets itself as Brazil's leading cloud-native PACS and telerradiology stack—HIPAA- and LGPD-oriented language on its site, AWS and Oracle Cloud hosting, ANVISA certification, and thousands of radiologist and clinic customers. A real compromise at this layer would not be a single-hospital outage; it would be a multi-tenant imaging pipeline feeding clinics that patients may never know by brand name.

That vendor concentration is why a forum claim this large gets indexed even before company confirmation: PACS vendors sit on DICOM studies, radiology reports, patient portals, and clinician credentials in one cloud footprint.

What is not confirmed

At catalog time Mobilemed had not published a customer notification, ANPD (Brazil's data protection authority) filing summary, or forensic bulletin matching the forum listing. Without that, every terabyte figure is actor marketing until samples are authenticated by independent researchers or the company acknowledges an incident.

Brazil's healthcare sector has seen prior leak-site noise—repackaged older imaging exports, mislabeled clinic dumps, and forum posts that borrow a real vendor logo with recycled CPF tables. Skepticism is warranted even when the victim logo is legitimate.

Why a PACS breach claim matters at 35M rows

Medical imaging data is not just names and emails. A PACS archive can hold:

  • Patient identifiers tied to specific exams and dates
  • Radiology reports describing diagnoses and clinical history
  • DICOM metadata linking studies to ordering physicians and facilities
  • Clinician and portal credentials enabling lateral access to more facilities

Fraud crews monetize PHI differently than card dumps—insurance impersonation, blackmail around sensitive imaging, and spear-phishing radiology staff with real patient context. At the actor-cited 35 million patient PII records, even a fraction being genuine would rank among the largest Brazilian healthcare exposures on record.

The ransom clock

Dark Web Informer noted an August 1, 2026 payment deadline—classic data-extortion choreography. Groups that never encrypt files still run the same playbook: exfiltrate, list, countdown, sell. Whether Mobilemed is negotiating privately or the listing is pure bluff, the public claim alone can trigger patient anxiety and clinic support-ticket floods.

What patients and clinics should do

  1. Ignore forum or Telegram download links claiming the full 23.5 TB archive—files may contain malware or unrelated recycled Brazilian identity dumps.
  2. Do not click SMS or WhatsApp "your exam results are ready" links unless you expected that message from a clinic you recognize; open patient portals via the clinic's official site or app.
  3. Clinic IT staff using Mobilemed should rotate shared credentials, review anomalous API access, and contact Mobilemed through official support channels—not forum intermediaries.
  4. Watch for ANPD or company notices; if Mobilemed confirms, expect LGPD notification timelines and facility-by-facility patient letters.
  5. Report suspected medical identity fraud to your health plan and Brazil's consumer channels if charges or appointments appear you did not authorize.

Canonical record

Mobilemed 2026 forum extortion claim on BreachHistory — indexed as unverified.

Sources: Dark Web Informer, Intel and Breaches, Mobilemed.