Ransomware Gang Seizes Hospital's Facebook Page
Ransomware attackers hijacked a hospital system's Facebook page during an active breach, claiming 6TB including mental health, abortion, and sexual assault records.
Active ransomware attack against a hospital system. The attackers are now posting from the victim’s own verified Facebook page — not spoofing a lookalike, posting from the seized real account — while the hospital is still in active incident response.
Recorded Future News reports the group claims 6 terabytes of exfiltrated data. Claimed contents: records tied to sexual assault cases, mental health treatment, abortions, and sexual harassment incidents. The hospital system has not been publicly named. The threat group’s identity has not been confirmed in available source reporting.
Confidence Labels
- Cyberattack ongoing: Confirmed.
- Facebook page compromised: Confirmed — attackers are actively posting from the account.
- 6TB exfiltration: Claimed by attackers. Not independently verified at time of publication.
- Specific record categories: Attacker claims. Treat as unconfirmed pending hospital disclosure.
The Social Media Pivot
This is an extortion escalation tactic, not a separate technical intrusion. Seizing a victim’s outward-facing communications channel during active incident response does three things:
- Splits the hospital’s response resources — recovering account access competes directly with breach containment
- Lets attackers address patients and media ahead of and around the hospital’s crisis messaging
- Creates visible, public pressure toward payment before legal and regulatory timelines can absorb it
The most sensitive data categories a hospital holds — mental health, sexual assault, abortion records — selected deliberately. The specificity of the claimed dataset is itself an escalation signal.
Where did the Facebook credentials originate? Likely the same initial access vector. This is unconfirmed — but any domain-joined machine or shared credential store that held the social media login was in scope the moment the attackers owned the network segment.
What Healthcare Security Teams Should Check Now
Don’t wait for an incident to discover these gaps:
- Are social platform admin credentials isolated from your primary identity store?
- Is the Facebook/LinkedIn admin account’s MFA recovery path on a device or email that can’t be owned through your corporate domain?
- Does your incident response runbook include a step for auditing and locking down external platform access — not just internal systems?
If your social media recovery flow routes through a corporate email account on a domain an attacker can control, they own your crisis communications too.
Recent ransomware coverage: Gunra gang exploiting Fortinet flaws and bypassing MFA and StormEncryptor, the China-linked operation.
Found this useful? Share it.


