INC New Zealand healthcare data leak
Data Leak
Summary
Hide ▲
Show ▼
INC stole and later published data from a healthcare organization in New Zealand, exposing a large amount of information and escalating the event from intrusion to leak publication. The stolen material appeared on a Dark Web leak site, increasing the likelihood of downstream misuse and wider disclosure. The exposure was tied to May 2025, making it a distinct data-leak event separate from the broader regional ransomware activity.
Related Happenings
BlackFile victims' Salesforce and SharePoint data leak
Data Leak
First: 24.04.2026 21:26
Last: 24.04.2026 21:26
Sources 1
About this happening:
BlackFile's **stolen documents** were published on a **dark web leak site**, exposing employee and business records taken from **Salesforce** and **SharePoint** environments. The...
BlackFile victims' Salesforce and SharePoint data leak
Data LeakAbout this happening: BlackFile's **stolen documents** were published on a **dark web leak site**, exposing employee and business records taken from **Salesforce** and **SharePoint** environments. The...
INC ransomware healthcare targeting campaign across Oceania
Campaign
First: 12.03.2026 00:00
Last: 12.03.2026 00:00
Sources 1
How related:
Cybersecurity authorities in Oceania are warning that the INC ransomware operation has been ripping through healthcare organizations in the region.
About this happening:
The **INC ransomware operation** has expanded its targeting of **healthcare organizations** across **Oceania**, increasing the risk of **service disruption** and **data theft**. T...
INC ransomware healthcare targeting campaign across Oceania
CampaignHow related: Cybersecurity authorities in Oceania are warning that the INC ransomware operation has been ripping through healthcare organizations in the region.
About this happening: The **INC ransomware operation** has expanded its targeting of **healthcare organizations** across **Oceania**, increasing the risk of **service disruption** and **data theft**. T...
Lazarus-associated Medusa extortion campaign targeting U.S. healthcare organizations
Campaign
First: 24.02.2026 13:00
Last: 24.02.2026 13:00
Sources 1
About this happening:
A **Lazarus**-associated **Medusa ransomware** campaign is targeting **U.S. healthcare organizations**, raising the risk of **extortion**, **data encryption**, and operational dis...
Lazarus-associated Medusa extortion campaign targeting U.S. healthcare organizations
CampaignAbout this happening: A **Lazarus**-associated **Medusa ransomware** campaign is targeting **U.S. healthcare organizations**, raising the risk of **extortion**, **data encryption**, and operational dis...
Barts Health NHS Trust invoice leak on Cl0p leak portal
Data Leak
First: 05.12.2025 20:55
Last: 05.12.2025 20:55
Sources 1
About this happening:
The **Barts Health NHS Trust** data leak became public when **Cl0p** posted stolen **invoice files** on its **dark-web leak portal**, exposing **full names and addresses** linked...
Barts Health NHS Trust invoice leak on Cl0p leak portal
Data LeakAbout this happening: The **Barts Health NHS Trust** data leak became public when **Cl0p** posted stolen **invoice files** on its **dark-web leak portal**, exposing **full names and addresses** linked...
Latest development: 08.12.2025 11:30
Barts Health NHS Trust is seeking a High Court order to stop the sharing, publication or use of invoice files stolen from its Oracle E-business Suite (EBS) database; the trust says Cl0p posted the files on the dark web, and it is working with NHS England, the National Cyber Security Centre, the Metropolitan Police and regulators including the Information Commissioner’s Office while its clinical systems remain unaffected.
Synnovis affected patients data leak
Data Leak
First: 12.11.2025 14:28
Last: 12.11.2025 14:28
Sources 1
About this happening:
Synnovis has begun notifying organizations after confirming that **stolen patient data** from its **June 2024 ransomware attack** included **NHS numbers, names, dates of birth, an...
Synnovis affected patients data leak
Data LeakAbout this happening: Synnovis has begun notifying organizations after confirming that **stolen patient data** from its **June 2024 ransomware attack** included **NHS numbers, names, dates of birth, an...
Timeline
-
12.03.2026 00:00 2 articles · 2mo ago
March 6 advisory discloses INC's New Zealand healthcare data leak
Initial DisclosureAustralian Cyber Security Centre, CERT Tonga, and New Zealand's National Cyber Security Centre issued a March 6 advisory describing INC's May 2025 theft of a large amount of data from a healthcare organization in New Zealand, followed by publication of the stolen material on a Dark Web leak site.
Show sources
- INC Ransomware Group Holds Healthcare Hostage in Oceania — www.darkreading.com — 12.03.2026 00:00
- INC Ransomware Group Holds Healthcare Hostage in Oceania — www.darkreading.com — 12.03.2026 00:00