rhysida ransomware actors claimed to have compromised Anne Arundel County, a US governmental body established in 1964, by exfiltrating 814,500 files totaling 2.6 TB, including sensitive medical, background-check, and Methadone clinic records governed by strict confidentiality rules. The stolen data allegedly spans medical faxes (2022–2026), medical-assistance documents containing SSNs and financial information, payroll/HR records, and jail gang-intelligence files. #UnitedStates
Incident Details
- Victim: Anne Arundel County
- Sector: Government & Defense
- Country: US
- Actor: rhysida
- Source: http://rhysidafohrhyy2aszi7bm32tnjat5xri65fopcxkdfxhi4tidsg7cad.onion/archive.php?company=281
- Discovered: 2026-10-09T19:38:34.194291+00:00
- Published: 2026-10-09T19:38:05.414569+00:00
Information
- 814,500 files totaling 2.6 TB were exposed
- 721 background-check dossiers contained full SSNs in filenames, including 2026 records
- Tens of thousands of medical faxes from 2022 to 2026 included patient names and diagnoses
- Methadone clinic records were included under 42 CFR Part 2 confidentiality protections
- 47,602 medical-assistance files contained driver licenses, Green Cards, SSN cards, tax forms, and bank data
- County payroll registers, HR memos, contracts, pension records, and discipline databases were exposed
- Jail gang-intelligence files and a gang-member master list were also compromised

Disclaimer: This post is based on public claims made by the ransomware group "rhysida". I cannot confirm the accuracy of the information. However, I would be happy to share any official statement from the affected organization to provide clarification.