Ransom! SIA Medical Centre (AUG-2026)

Ransom! SIA Medical Centre (AUG-2026)
The ransomware incident affecting SIA Medical Centre in Latvia involves the threat actor rhysida, resulting in disclosure of approximately 20,000 patient records including medical dossiers, clinical notes, and insurance/work-cover files, as well as staff identity and HR documents. The claim also includes theft of plaintext credentials for clinical and government systems and exposure of legal/financial records, impacting Latvia #latvia

Incident Details

  • Victim: SIA Medical Centre
  • Sector: Healthcare
  • Country: LV
  • Actor: rhysida
  • Source: http://rhysidafohrhyy2aszi7bm32tnjat5xri65fopcxkdfxhi4tidsg7cad.onion/archive.php?company=258
  • Discovered: 2026-08-13T17:57:28.008533+00:00
  • Published: 2026-08-13T17:56:55.126638+00:00

Information

  • SIA Medical Centre was established in 1993 by Dr Martin Sia in Melbourne’s northwest.
  • The organisation operates 9 clinics: Box Hill, Burwood, Croydon, Essendon, Footscray, Moonee Ponds, Montrose, Mulgrave, and Berwick.
  • Approximately 20,000 patient medical records were exposed, including names, dates of birth, Medicare numbers, clinical notes, insurance files, work-cover files, and full patient dossiers.
  • Staff identity documents were disclosed, including passports, driver’s licenses, police checks, and tax file declarations for doctors and employees.
  • Plaintext credentials were included, with logins and passwords for clinical systems such as Synapse imaging, PRODA, terminal servers, and doctor accounts.
  • HR records were compromised, including signed employment contracts, staff incident reports, and immunisation registers.
  • Legal and financial documents were also taken, including subpoenas, complaints, Bupa contracts, bank details, and provider payment forms.

Disclaimer: This post is based on public claims made by the ransomware group "rhysida". I cannot confirm the accuracy of the information. However, I would be happy to share any official statement from the affected organization to provide clarification.

monitored by: ransomware.live