LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Dar Al Teb Listed by gunra Ransomware Group

HIGH severityUnverified claimHow we verify

Dar Al Teb Listed by gunra Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·April 7, 2025
Dar Al Teb Listed by gunra Ransomware Group

Reported April 7, 2025.

HIGH
Severity
April 7, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Dar Al Teb has been listed by the gunra ransomware group, which claims to have exfiltrated internal files. The incident was disclosed on 7 April 2025; the number of people affected is not stated, so anyone connected to the organisation should check for notices and take protective steps.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Healthcare organisations remain a frequent target for ransomware groups that combine encryption with data theft, seeking leverage from the sensitivity of medical records and the operational pressure on hospitals. Against that backdrop, Dar Al Teb, a hospital and healthcare provider, was listed on 7 April 2025 by the ransomware group known as gunra, which claims to have exfiltrated internal files during an attack.

Public detail on the incident is limited. The number of people affected has not been disclosed, and independent confirmation of the group's claims has not been reported. What is known is that the listing places the organisation among those whose data gunra says it has taken, raising practical questions for patients, staff and partners whose information may be involved.

What happened

According to the available record, Dar Al Teb was listed by the gunra ransomware group on 7 April 2025. The group asserts that internal files were exfiltrated in a ransomware attack. No further public detail has been provided on the precise date of the intrusion, the method of access, the volume of data taken, or whether systems were encrypted. The number of individuals whose information may be involved remains unknown. The listing itself constitutes a claim by the group rather than independently verified confirmation of every asserted detail.

Who is gunra?

Gunra is a ransomware operation that has appeared in public reporting as a double-extortion actor: it encrypts systems and simultaneously steals data, then pressures victims by threatening to publish or sell the material on a dedicated leak site. Like other groups in this category, it typically posts victim names and sample claims to increase urgency. Its listings are statements of intent or assertion; they do not automatically prove the full scope of any single intrusion. Prior public activity associated with the name has followed the familiar pattern of targeting organisations across sectors and using leak-site pressure as a core tactic. Nothing in the public record of this particular listing expands those general methods into confirmed specifics about Dar Al Teb beyond the claim of internal-file exfiltration.

Who is Dar Al Teb?

Dar Al Teb is identified in the record as operating in the hospital and healthcare sector. Organisations of this type routinely manage clinical records, patient demographics, appointment and billing data, staff information, and internal administrative files. A breach involving such an entity is consequential because healthcare data is both highly personal and long-lived: medical histories, contact details and identifiers can be reused for fraud, social engineering or further targeting long after an incident. The organisation's role in delivering care also means any disruption or loss of confidence can affect patients and partners beyond the immediate data exposure.

The information in question

The facts state that internal files were exfiltrated in a ransomware attack. No more granular inventory—such as patient records, financial documents, credentials or specific file counts—has been publicly disclosed. Healthcare providers typically hold medical histories, identifiers, contact information, insurance or billing details, and internal operational documents. Because the exact contents of the claimed exfiltration remain unconfirmed, it is not possible to state which of these categories, if any, were included. Readers should treat the exposure as potentially involving sensitive internal material while recognising that the precise scope is unknown.

Why it matters

For individuals, the practical risks include identity fraud, targeted phishing that references real medical or personal details, and long-term misuse of health-related information that is difficult to change. Even when the full contents of a leak are unclear, the mere assertion that internal files left an organisation can enable social-engineering attempts that appear more credible. For Dar Al Teb, the consequences include potential regulatory scrutiny, the cost of investigation and remediation, reputational damage, and the operational burden of determining what was taken and notifying those affected. Because the number of people involved is unknown, the scale of any required response remains open. The incident also illustrates the broader pressure ransomware groups place on healthcare providers, where continuity of care and patient trust are at stake alongside data confidentiality.

If your data was in this claimed breach

If you have been a patient, employee or partner of Dar Al Teb, treat the possibility of exposure seriously even though the exact data types and numbers remain undisclosed. Monitor financial and medical accounts for unusual activity, be cautious of unsolicited messages that reference healthcare details, and consider placing fraud alerts with relevant credit or identity services where available. Change passwords on related accounts and enable multi-factor authentication where it is offered. You can also run a free exposure scan of your email address to check whether your information has already appeared in known breach data sets; such checks do not prove involvement in this specific incident but can surface other exposures that warrant attention. If Dar Al Teb or a regulator issues formal notification, follow the guidance provided in that notice.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyDar Al Teb security record
87/100
DoxxScan™ · Low doxx risk
B 80Good record

1 reported incident on record.

See Dar Al Teb’s full breach history →

More recent breaches

American Hospital Dubai Listed by gunra Ransomware GroupJune 5, 2025Bioprofarma Bagó S.A Listed by gunra Ransomware GroupApril 27, 2025KUKJE PHARM CO.,LTD Listed by gunra Ransomware GroupApril 8, 2026NeoDerm Listed by gunra Ransomware GroupApril 8, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the Dar Al Teb Listed by gunra Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by gunra — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram