Hematology Oncology Consultants Listed by rhysida Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Hematology Oncology Consultants was listed by the Rhysida ransomware group on September 20, 2025, after internal files were exfiltrated in a ransomware attack. The number of people affected is not known; anyone who received services from the practice should review statements from the organization and consider placing fraud alerts or credit monitoring.
Patients and staff connected to Hematology Oncology Consultants may now face the practical consequences of a claimed ransomware incident in which internal files were reportedly taken. When a medical practice that treats cancer and blood disorders appears on a ransomware group's listing, the immediate concern is whether personal health details, contact information or other sensitive records could be misused for identity theft, targeted fraud or unwanted contact. Public detail remains limited, so the full picture of who is affected and what exactly left the network is not yet clear.
What is known so far is that the organisation was listed by the rhysida ransomware group on or around 20 September 2025. The listing itself is a claim by the attackers; independent confirmation of the full scope has not been publicly detailed. For anyone who has received care or worked at the practice, the prudent step is to treat the possibility of exposure seriously while waiting for further official information.
What happened
According to available reporting, Hematology Oncology Consultants was listed by the rhysida ransomware group. The reported date associated with the listing is 20 September 2025. The facts state that internal files were exfiltrated in a ransomware attack. The number of people affected is unknown, and no further public detail has been provided on the precise timing of the intrusion, the method of initial access, the volume of data taken, or whether systems were encrypted in addition to the claimed exfiltration. Because the listing originates from the threat actor, it remains an unverified claim until corroborated by the organisation or independent investigators.
No official statement from Hematology Oncology Consultants detailing the incident has been included in the available facts. In such cases, organisations typically conduct forensic reviews and notify regulators and affected individuals once the investigation reaches a clearer stage. Until then, the public record consists primarily of the group's claim that internal files were removed.
The group behind it: rhysida
Rhysida is a ransomware operation that became publicly visible in 2023. It functions as a ransomware-as-a-service model, in which affiliates carry out attacks and share proceeds with the core developers. The group is known for double-extortion tactics: encrypting systems while also stealing data and threatening to publish it on a dedicated leak site if a ransom is not paid. Rhysida has previously targeted organisations across healthcare, education, government and private industry, often posting victim names and sample files to pressure payment.
Like other groups of this type, rhysida typically gains initial access through phishing, exploitation of unpatched remote services or compromised credentials, then moves laterally to locate valuable data before deploying encryption and exfiltration tools. Its leak site serves both as a pressure mechanism and as a public claim of responsibility. In this instance, the appearance of Hematology Oncology Consultants on that site is presented by the group as evidence of a successful attack; it does not by itself confirm every detail of the intrusion or the exact contents of any stolen files.
Hematology Oncology Consultants and its sector
Hematology Oncology Consultants, also referenced in connection with Michigan Hematology Oncology, is a private medical practice focused on the diagnosis and treatment of cancer and blood disorders. Practices of this kind provide specialised outpatient and consultative care, coordinating chemotherapy, blood-product management, laboratory monitoring and long-term follow-up for patients facing serious illness. They operate within the broader U.S. healthcare sector, which is heavily regulated under laws such as HIPAA because of the sensitivity of the information they handle.
A breach involving a hematology-oncology practice carries particular weight because the data such organisations typically maintain can include diagnoses, treatment histories, laboratory results, insurance details and demographic information. Even when only “internal files” are described, the clinical context means those files may contain material that is both personally identifiable and medically sensitive. Healthcare providers remain frequent targets for ransomware groups precisely because the combination of operational disruption and data sensitivity creates strong leverage for extortion.
What data was at risk
The available facts state that internal files were exfiltrated in the ransomware attack. No more granular inventory—such as patient names, Social Security numbers, clinical notes, billing records or employee data—has been publicly disclosed. The number of individuals potentially affected is listed as unknown. Therefore it is not possible to confirm the exact categories or volume of information that left the organisation’s systems.
Organisations of this type routinely hold protected health information, contact details, insurance identifiers and administrative records. In the absence of a confirmed data inventory from the practice or regulators, any assumption about specific data elements would be speculative. Readers should treat the exposure of internal files as a serious but still incompletely defined risk until official notifications clarify the contents.
Why it matters
For patients, the practical risk is that medical and personal details could be used for identity theft, insurance fraud, phishing campaigns that reference real diagnoses, or blackmail. Even limited internal documents can contain enough context for criminals to craft convincing social-engineering attacks. Staff whose employment or administrative records were among the files face similar exposure of personal identifiers and workplace information.
For the organisation, a claimed ransomware incident can disrupt clinical operations, trigger regulatory scrutiny, generate notification and remediation costs, and erode patient trust. Healthcare practices must balance the need for rapid recovery of systems with careful investigation and lawful notification of affected individuals. Because the number of people affected remains unknown, the full scale of these consequences cannot yet be measured.
The incident also illustrates the broader pattern of ransomware groups focusing on medical specialties that manage high-stakes patient data. Even when encryption is not confirmed, the mere claim of exfiltration creates lasting uncertainty for those whose information may have been involved.
If your data was in this claimed breach
If you have been a patient or employee of Hematology Oncology Consultants, monitor financial accounts and credit reports for unusual activity and consider placing a fraud alert or credit freeze with the major credit bureaus. Be alert for phishing emails or calls that reference medical treatment or personal details; do not click links or provide information in response to unsolicited contact. Review any official breach notification you may receive from the practice for specific guidance on free credit monitoring or other remedies.
You can also run a free exposure scan of your email address to check whether your information has already appeared in known breach data sets. Doing so provides an additional early-warning signal while you wait for further details from the organisation or regulators. Keep records of any suspicious activity and report confirmed identity theft to the appropriate authorities.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
MACT Health Board Listed by rhysida Ransomware GroupHeart South Cardiovascular Group Listed by rhysida Ransomware GroupInvacare Listed by rhysida Ransomware GroupCytek Biosciences Listed by cmdorganization Ransomware GroupLatest breaches
Publicly posted by rhysida — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.