← Mobilemed

2026 Mobilemed — forum extortion claim; 35M patient PII cited; 23.5 TB (unverified)

2026 35.0M records affected Share on X

Data compromised

Actor-claimed: 23.5 TB / 52.2 million files including 35 million patient PII records, 17,176,370 personal files, 67,493 account PII records, sensitive patient information, and internal credentials—unverified

Technical writeup

Unverified criminal-forum extortion claim — observed July 10–11, 2026. Dark Web Informer and Intel and Breaches (IBreaches) reported a threat actor advertised on an underground forum that they breached Mobilemed, a Brazil-based cloud Picture Archiving and Communication System (PACS) and telerradiology platform serving hospitals, radiologists, and diagnostic centers. The listing claims approximately 52.2 million files totaling 23.5 TB, including 35 million patient personally identifiable information records, 17,176,370 personal files, 67,493 account PII records, sensitive patient information, and internal credentials. The actor demanded a $1.5 million ransom with an August 1, 2026 payment deadline and threatened to sell the data if unpaid. Mobilemed had not issued a matching public breach confirmation at indexing time. BreachHistory indexes the actor-cited 35 million patient PII figure labeled unverified.

Root cause

Unverified underground-forum listing alleging ransomware/data-extortion breach of Brazilian cloud PACS vendor Mobilemed—company had not confirmed at catalog time

References