Ransom! PARTNERED HEALTH GROUP (JUL-2026)

Ransom! PARTNERED HEALTH GROUP (JUL-2026)
In June 2026, incransom compromised Australia-based Partnered Health Group, exfiltrating 3.2 TB of data—including 27 years of patient records, payroll/HR files, and multiple SQL and Best Practice database backups—from 21 servers across 21 clinics. The stolen dataset also includes Bupa corporate billing and program information, placing patients and staff in Australia at risk of further exposure. #Australia

Incident Details

  • Victim: PARTNERED HEALTH GROUP
  • Sector: Healthcare
  • Country: AU
  • Actor: incransom
  • Source: http://incblog6qu4y4mm4zvw5nrmue6qbwtgjsxpw6b7ixzssu36tsajldoad.onion/blog/disclosures/6a6b75a95ae71db30c8b0b19
  • Discovered: 2026-07-30T16:30:13.670561+00:00
  • Published: 2026-07-30T01:00:00+00:00

Information

  • Healthcare provider in Australia with 60+ clinics nationwide, operating under brands including Partnered Health Medical Centres, Jobfit, Baseline Onsite, New View Psychology, NewPsych, Australian EAP, Fuel Your Life, Northcare Physio, and TeleWell.
  • Owned by Quadrant Private Equity and reportedly in the process of a pending acquisition by Bupa for about AUD 450 million, with ACCC and FIRB approval still pending.
  • Unauthorized access reportedly occurred on 23 June 2026, with 3.2 TB of data exfiltrated across 2,298,203 files from 21 servers.
  • Compromised systems included 9 Active Directory controllers, 11 Best Practice Medical servers, and 1 central SQL server.
  • SQL databases reportedly taken included ZedMed, Payroll, DocPays, VectraplexECG, BPM, and more than 1,100 SQL backups.
  • At least 21 clinic locations across five states and territories were affected, with 17,727+ named patient files identified.
  • Stolen data allegedly spans 1999 to 2026 and includes complete patient medical records, consultation notes, referral letters, pathology results, diagnostic imaging reports, and prescriptions.
  • Reportedly exposed staff records include employment contracts, passport scans, AHPRA registrations, tax declarations, superannuation details, and performance reviews.
  • Additional material allegedly includes Bupa corporate billing agreements, fund tables, patient invoices, corporate program documents, and active portal session cookies.
  • Financial and governance data reportedly includes QuickBooks records from 2004 to 2026, Medicare billing, DVA remittances, private health fund claims, RACGP accreditation files, patient consent templates, and internal audit data.
  • The group claims negotiations were ignored for 22 days and has threatened staged publication of file listings, HR records, SQL databases, corporate data, and a full public data dump if no settlement is reached within 10 days.

Disclaimer: This post is based on public claims made by the ransomware group "incransom". I cannot confirm the accuracy of the information. However, I would be happy to share any official statement from the affected organization to provide clarification.

monitored by: ransomware.live