In the US, ransomware group incransom claims it exfiltrated and analyzed 7 terabytes of Horizon Family Medical Group data, including patient records and 6TB of mission-critical SQL and QuickBooks databases, threatening confidentiality and business operations. The actor’s post alleges the data contains sensitive clinical, financial, and behavioral health information and frames it as being preserved for long-term exposure. #UnitedStates
Incident Details
- Victim: Horizon Family Medical Group
- Sector: Healthcare
- Country: US
- Actor: incransom
- Source: http://incblog6qu4y4mm4zvw5nrmue6qbwtgjsxpw6b7ixzssu36tsajldoad.onion/blog/disclosures/6a3399265ae71db30c9a6e23
- Discovered: 2026-06-18T07:23:32.673547+00:00
- Published: 2026-06-18T01:00:00+00:00
Information
- Complete internal data exposure totaling 7 terabytes, including patient records, file data, SQL databases, and QuickBooks financial data.
- Patient information reportedly includes visit histories, diagnoses, prescriptions, lab results, and private physician notes.
- Sensitive women’s health records are said to include gynecological exams, pregnancies, abortions, Pap smear results, STD diagnoses, and treatments.
- Behavioral health data allegedly contains psychiatric diagnoses, psychotherapy session notes, and antidepressant or antipsychotic prescriptions.
- Additional medical files reportedly cover allergies, medication reactions, ophthalmology records, and nutrition or weight-management information.
- Business databases are described as containing patient flow, schedules, office utilization, and revenue metrics by department and doctor.
- Financial records allegedly include transactions, salaries, executive bonuses, tax reports, debts, loans, and insurance or supplier settlements.
- The exposed data is presented as enough to reveal operational profitability, customer value, and other sensitive business metrics.
- The information is described as being prepared for long-term archival and distributed storage, making it effectively irrecoverable.
- The leak is framed as a lasting consequence of poor data protection and a serious threat to both patients and business operations.

Disclaimer: This post is based on public claims made by the ransomware group "incransom". I cannot confirm the accuracy of the information. However, I would be happy to share any official statement from the affected organization to provide clarification.