2026 Mobilemed — forum extortion claim; 35M patient PII cited; 23.5 TB (unverified)
Data compromised
Actor-claimed: 23.5 TB / 52.2 million files including 35 million patient PII records, 17,176,370 personal files, 67,493 account PII records, sensitive patient information, and internal credentials—unverified
Technical writeup
Unverified criminal-forum extortion claim — observed July 10–11, 2026. Dark Web Informer and Intel and Breaches (IBreaches) reported a threat actor advertised on an underground forum that they breached Mobilemed, a Brazil-based cloud Picture Archiving and Communication System (PACS) and telerradiology platform serving hospitals, radiologists, and diagnostic centers. The listing claims approximately 52.2 million files totaling 23.5 TB, including 35 million patient personally identifiable information records, 17,176,370 personal files, 67,493 account PII records, sensitive patient information, and internal credentials. The actor demanded a $1.5 million ransom with an August 1, 2026 payment deadline and threatened to sell the data if unpaid. Mobilemed had not issued a matching public breach confirmation at indexing time. BreachHistory indexes the actor-cited 35 million patient PII figure labeled unverified.
Root cause
Unverified underground-forum listing alleging ransomware/data-extortion breach of Brazilian cloud PACS vendor Mobilemed—company had not confirmed at catalog time