GENERAL SANTOS CITY, Philippines — The Rhysida ransomware group has publicly claimed that it breached General Santos Doctors Hospital (GSDH) and stole approximately 2.44 terabytes of data comprising more than 3.5 million files, raising concerns over the possible exposure of sensitive medical, personal, employee, financial and corporate information.

However, General Santos Doctors Hospital has not confirmed that a cyberattack or data breach occurred. In a public advisory issued September 11, the hospital said its Management Information Systems (MIS) team immediately began assessing and securing its information systems after receiving reports of the alleged breach.

“Based on the initial assessment, no indicators of unauthorized access, system compromise, ransomware activity or data exfiltration have been established at this time,” GSDH said in its advisory.

The hospital said it is continuing to monitor, investigate and validate its systems and will take appropriate action based on verified findings. It also said that if a security incident requiring notification is eventually confirmed, it will comply with applicable laws and regulations.

Rhysida posts alleged hospital data on leak site

The allegations surfaced on a ransomware leak site operated by Rhysida, where the group listed GSDH as an alleged victim and claimed possession of 3,502,636 files totaling about 2.44 TB.

The listing reportedly gave the hospital a seven-day deadline to respond to the extortion demand. Rhysida demanded 8 Bitcoin (BTC) in exchange for the alleged data and threatened to sell the information if its demand was not met.

The group claimed that the data would be sold exclusively to a single buyer rather than repeatedly resold to multiple parties.

The publication of the listing, however, does not by itself establish that the claimed breach actually occurred or that the volume and contents of the alleged data are genuine. Ransomware groups have an incentive to pressure alleged victims through public claims, and such claims require independent verification.

Screenshots accompanying the listing purportedly show documents allegedly taken from the hospital, including what appears to be hospital and administrative material.

Alleged patient records among the data

If the ransomware group’s claims are eventually validated, the alleged dataset could represent a significant privacy and cybersecurity incident because of the breadth of information it supposedly contains.

According to the Rhysida listing, the largest portion of the alleged stolen data involves patient and medical information.

The group claims to have obtained patient records and medical scans associated with several hospital departments, including surgical pathology, hemodialysis and admissions.

It also claims to have accessed alleged cancer-center dossiers containing information associated with PhilHealth identification numbers, laboratory quotations and cancer-marker testing, including dates of birth.

The listing further claims that PhilHealth-related claims-monitoring information and neonatal intensive care unit (NICU) data were included.

The alleged presence of NICU records is particularly sensitive because such information could involve medical and identifying details concerning newborn patients and their families.

Employee and healthcare professional information allegedly included

The alleged breach is not limited to patient information.

Rhysida also claims that information concerning hospital employees and healthcare professionals was taken from the network.

Among the alleged files is an accredited physicians register that supposedly contains mobile phone numbers, professional license information and PhilHealth identification numbers.

The group also claims to possess payroll workbooks, including records associated with an affiliated diagnostic center, as well as human-resources dossiers, passport scans and drug-testing files.

These claims, if confirmed, could expose a broad range of personally identifiable information belonging not only to patients but also to hospital personnel and medical professionals.

Financial and corporate records also allegedly compromised

Rhysida’s listing further claims access to the hospital’s financial, accounting and governance documents.

The alleged dataset reportedly includes audited financial statements, some of which supposedly carry signatures of senior hospital officials such as the chairman, treasurer or chief financial officer.

The group also claims to have obtained Bureau of Internal Revenue-related documents and balance sheets, as well as information involving bank accounts maintained across more than six banks.

Other allegedly stolen documents include internal audit memoranda concerning reported cashier discrepancies and cash shortages, along with payroll bank-upload batches.

The ransomware group also claims access to corporate records, including Securities and Exchange Commission-related shareholders’ meeting minutes and documents concerning related-party entities stored on network shares.

The listing further alleges that personal contact information belonging to senior hospital officials—including the hospital president, administrator and members of the board—was included in the data.

No evidence yet of hospital operations being disrupted

Despite the scale of the alleged data theft, the available information does not establish whether GSDH’s systems were encrypted by ransomware or whether hospital services were disrupted.

At present, the publicly available material centers on an extortion and data-theft claim posted by Rhysida, while GSDH’s own September 11 assessment says it has not established evidence of unauthorized access, system compromise, ransomware activity or data exfiltration.

That distinction is critical.

A ransomware leak-site posting is an allegation by a threat actor, not an independent forensic finding. Confirmation would require evidence from the hospital’s technical investigation, cybersecurity specialists, law-enforcement authorities or other credible independent sources.

Potential consequences if breach is confirmed

If the allegations are ultimately substantiated, the incident could have serious implications because of the alleged combination of medical, identification, employment, financial and corporate information.

Medical records may contain highly sensitive information about a person’s medical history, diagnosis, treatment, laboratory results and other private circumstances. When combined with names, identification numbers, birth dates, contact details, employment records and financial information, such data could potentially be exploited for identity theft, fraud, phishing, targeted scams and other forms of abuse.

The alleged inclusion of passport scans and professional-license information could also increase risks for affected individuals if such records were genuinely taken and subsequently exposed or sold.

For a healthcare institution, the issue extends beyond data privacy. Hospitals depend heavily on information systems for admissions, medical records, diagnostics, billing, laboratory services and other essential functions. A confirmed ransomware intrusion can therefore create operational and patient-safety risks even when clinical systems are not immediately shut down.

Rhysida’s history of targeting healthcare organizations

Rhysida emerged in 2023 and has operated as a ransomware-as-a-service (RaaS) cybercrime operation. Security researchers and government agencies have documented the group’s targeting of organizations in sectors including healthcare, government and education.

The group has become associated with double-extortion tactics, in which attackers steal data and use the threat of public disclosure or sale as additional leverage for ransom payments.

The leak-site model is designed to increase pressure on victims by publicly announcing an alleged compromise and setting deadlines for negotiations. If negotiations fail, attackers may threaten to publish or sell the stolen information.

Cybersecurity authorities and researchers have previously warned about Rhysida’s activity against healthcare and other organizations, making the group’s claim involving GSDH a matter that warrants close scrutiny.

GSDH: Investigation remains ongoing

GSDH, for its part, said it is treating the allegations seriously and has already mobilized its MIS team to assess and secure its systems.

The hospital said it remains committed to protecting the privacy and security of information entrusted to it and will issue official updates as verified and material information becomes available.

For now, the central question remains unresolved: whether Rhysida actually gained unauthorized access to GSDH systems and exfiltrated the massive volume of data it claims to possess.

Until the hospital’s technical investigation or other independent evidence confirms the allegations, the reported 2.44-terabyte breach and the alleged exposure of 3.5 million files should be treated as unverified claims by the ransomware group.

The hospital’s September 11 advisory remains the latest official position provided by GSDH, and it states that no indicators of unauthorized access, system compromise, ransomware activity or data exfiltration had been established as of its initial assessment.

Back to top