Ransom! hsc.mb.ca (OCT-2026)
The Health Sciences Centre (hsc.mb.ca) in Winnipeg, Canada, was targeted by the ransomware threat actor incransom, resulting in what they claim was the largest healthcare data breach in the sector, while they asserted they chose not to fully disrupt operations. They alleged access/exfiltration of patient, employee, financial/insurance, and confidential hospital materials, despite management stating no sensitive data was affected. #Canada

Incident Details

  • Victim: hsc.mb.ca
  • Sector: Healthcare
  • Country: CA
  • Actor: incransom
  • Source: http://incblog6qu4y4mm4zvw5nrmue6qbwtgjsxpw6b7ixzssu36tsajldoad.onion/blog/disclosures/6acad92e9cd108bf2630db9c
  • Discovered: 2026-10-11T01:14:06.099529+00:00
  • Published: 2026-10-10T10:00:00+00:00

Information

  • The Health Sciences Centre in Winnipeg, one of the largest medical institutions, was targeted, resulting in the largest data breach among healthcare institutions.
  • The group chose not to fully disrupt the facility’s operations, recognizing the potentially devastating impact such an action could have had on patients’ lives and health.
  • Health Sciences Centre management stated that no sensitive data had been affected, despite having been informed otherwise.
  • The exposed information included patient medical records such as full names, dates of birth, addresses, phone numbers, hospital medical record numbers, diagnoses, medical history, allergies, medications, laboratory results, imaging reports, appointment dates, treatment details, and physician information.
  • Employee and healthcare professional data was also included, including names, contact details, dates of birth, employee numbers, employment records, payroll and banking information, professional credentials, work schedules, and departmental assignments.
  • Financial and insurance information was exposed, including billing records, payment histories, and insurance or benefits claim information.
  • Confidential hospital documents were also part of the breach, such as internal emails, staff communications, system configurations, network diagrams, security procedures, database backups, and exported spreadsheets.
  • The group stated it would have preferred not to make the breach public, but said management left no other choice.

Disclaimer: This post is based on public claims made by the ransomware group "incransom". I cannot confirm the accuracy of the information. However, I would be happy to share any official statement from the affected organization to provide clarification.

monitored by: ransomware.live