Cookeville Regional Medical Center Listed by rhysida Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Cookeville Regional Medical Center was listed by the Rhysida ransomware group on July 13, 2025, following the exfiltration of internal files in a ransomware attack. Individuals who may have been affected should review the organization’s notices and take steps to protect their information.
On July 13, 2025, Cookeville Regional Medical Center appeared on a listing associated with the rhysida ransomware group. Public reporting indicates the group claims to have carried out a ransomware attack that involved the exfiltration of internal files. The number of people whose information may be involved remains unknown, and further specifics about the incident have not been disclosed.
For patients, staff, and others connected to a regional medical center, any claim of data removal carries practical weight. Health-care organizations routinely hold records that can be used for identity misuse, insurance fraud, or targeted scams. Even when exact contents and scale stay unconfirmed, the mere listing raises the need for awareness and basic protective steps among those who have interacted with the facility.
Inside the incident
Public detail on the incident is limited to the July 13, 2025 report that Cookeville Regional Medical Center had been listed by the rhysida ransomware group. The available summary states that internal files were exfiltrated in a ransomware attack. No confirmed figure for the number of people affected has been released, nor have precise dates of intrusion, methods of initial access, or the volume of data involved been made public. The listing itself constitutes a claim by the group rather than an independently verified confirmation of every asserted detail. Beyond the statement that internal files were taken, the exact sequence of events and the full scope of the compromise remain undisclosed.
Who is rhysida?
Rhysida is a ransomware operation that has been active in public view since mid-2023. The group is known for a double-extortion model: encrypting systems while also removing copies of data and threatening to publish them on a dedicated leak site if payment is not made. It has listed organizations across multiple sectors, including health care, education, and government, often posting sample files or directories as purported proof. Rhysida has operated with a relatively polished public presence, using a Tor-based site to name victims and set deadlines. Its tactics typically include phishing or exploitation of unpatched services for initial access, followed by lateral movement and data staging before encryption. These patterns are drawn from widely reported activity across many incidents; they do not constitute verified specifics about the Cookeville Regional Medical Center listing, which should be treated as an unverified claim by the group.
Who is Cookeville Regional Medical Center?
Cookeville Regional Medical Center is a health-care provider serving patients in its local region. Like other community and regional hospitals, it delivers clinical care, diagnostic services, and related administrative functions. Organizations of this type maintain electronic health records, billing systems, insurance information, employee data, and operational files necessary for day-to-day patient care and compliance with health-care regulations. A breach claim against such an institution is consequential because the data it holds can include sensitive personal and medical details that, if misused, affect individuals long after any technical disruption ends. The center’s own public description emphasizes its role in providing quality care and community impact, underscoring the trust placed in it by patients and staff.
The information in question
The only data category named in public reporting is “internal files” said to have been exfiltrated during the ransomware attack. No further breakdown—such as whether patient records, employee information, financial documents, or other categories were included—has been disclosed. Exact contents therefore remain unconfirmed. Health-care organizations of this kind typically store protected health information, demographic details, insurance identifiers, contact data, and internal administrative records. Until more precise inventories are released by the organization or verified independently, it is not possible to state which of these, if any, were among the files claimed by the group.
The real-world impact
For individuals, the primary risks center on the potential misuse of personal or medical information. Even limited internal files can contain enough identifiers to support identity theft, fraudulent insurance claims, or highly targeted phishing that references real medical history. Because the number of people affected is unknown, anyone who has been a patient, employee, or contractor may reasonably treat the situation as a prompt to monitor accounts and credit activity. For the medical center itself, a ransomware incident can interrupt clinical systems, divert staff time to recovery and notification duties, and create ongoing compliance and reputational costs. These effects are concrete but vary widely depending on how much data was actually taken and how quickly systems were restored—details that remain undisclosed in this case.
Were you affected?
If you have received care at, worked for, or otherwise shared information with Cookeville Regional Medical Center, begin with basic precautions. Review bank and credit-card statements for unfamiliar charges, place a free fraud alert or credit freeze with the major credit bureaus, and be alert for unexpected emails or calls that reference medical details. Change passwords on any accounts that may have used the same credentials associated with the facility, and enable multi-factor authentication where available. Because the precise data involved has not been confirmed, these steps are precautionary rather than a response to verified exposure. Readers can also run a free exposure scan of their email address to check whether that address has already appeared in known breach data sets; such a scan provides one additional data point but does not replace ongoing personal monitoring.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
MACT Health Board Listed by rhysida Ransomware GroupHeart South Cardiovascular Group Listed by rhysida Ransomware GroupInvacare Listed by rhysida Ransomware GroupCytek Biosciences Listed by cmdorganization Ransomware GroupLatest breaches
Publicly posted by rhysida — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.