MNGI Digestive Health2 Listed by alphv Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The MNGI Digestive Health2 Listed by alphv Ransomware Group (reported September 24, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
On September 24, 2023, MNGI Digestive Health2 was listed by the alphv ransomware group as a victim of a ransomware attack in which internal files were claimed to have been exfiltrated. The number of people affected remains unknown, and public detail on the incident is limited to the group's listing and the description of internal files taken during the attack.
For patients and others connected to a specialized digestive-health practice, any confirmed exposure of internal material raises practical questions about what information may have left the organisation's control and what steps are available in response. At present, the listing itself stands as an unverified claim by the group rather than an independently confirmed account of the full scope.
Inside the incident
Public reporting on the matter centers on the September 24, 2023 listing of MNGI Digestive Health2 by alphv. According to the available facts, the group asserted that internal files had been exfiltrated in a ransomware attack. No further Reported Details have been provided regarding the precise timing of any intrusion, the method of initial access, the volume of data involved, or whether encryption of systems also occurred. The number of individuals potentially affected is listed as unknown.
Because the primary public signal is the threat actor's own leak-site claim, independent verification of the full sequence of events has not been established in the material available. Organisations facing such listings sometimes later issue their own notices; no such additional confirmation is included in the facts at hand. The incident is therefore best understood, on current information, as a claimed ransomware event involving the exfiltration of internal files, with scale and technical particulars undisclosed.
Inside alphv
alphv, also widely known in public reporting as BlackCat, is a ransomware operation that has functioned on a ransomware-as-a-service model. The group has been documented as deploying double-extortion tactics: encrypting victim systems while also copying data and threatening to publish or auction it if demands are not met. Listings on its leak site have served as a pressure mechanism and as a public assertion that a given organisation has been compromised.
Public knowledge of alphv includes a history of targeting organisations across multiple sectors, often with customisable ransomware written in modern languages and with an emphasis on negotiation and timed data releases. The group has been associated with high-profile campaigns prior to and around the period of this listing. None of that established background, however, supplies verified specifics about the MNGI Digestive Health2 matter beyond the claim that the organisation was listed and that internal files were said to have been exfiltrated. Any statements attributed to alphv about this victim should be treated as the group's own assertions unless corroborated by other sources.
About MNGI Digestive Health2
MNGI Digestive Health is described as a physician practice founded in 1973 and headquartered in Minneapolis, Minnesota. It specialises in the diagnosis and treatment of disorders of the digestive system. Practices of this type typically maintain clinical records, scheduling and billing information, communications with referring physicians, and administrative files necessary to operate a multi-provider medical group.
A breach or claimed exfiltration affecting such an organisation is consequential because digestive-health practices handle sensitive health information and related personal identifiers as a routine part of care. Even when the exact contents of any taken files remain unconfirmed, the sector context means that patients, staff, and business partners have a legitimate interest in understanding what is known and what protective steps remain available. The facts do not establish negligence or specific security failures; they establish only that the organisation was named in connection with an alphv listing.
The information in question
The facts state that internal files were exfiltrated in a ransomware attack. No more granular inventory of data types—such as particular categories of patient records, financial documents, or employee information—has been disclosed in the available material. The number of people affected is unknown.
Organisations of this kind ordinarily hold protected health information, contact and insurance details, clinical notes, and internal operational documents. It is not possible, on the given facts, to confirm which of those categories, if any, were included in the material alphv claims to have taken. Readers should therefore treat the precise contents as unconfirmed while recognising that internal files from a medical practice can encompass a range of sensitive material.
The real-world impact
For individuals whose information may have been among any exfiltrated files, the practical risks include potential misuse of personal or health-related data for social engineering, identity theft, or targeted fraud. Because the scale and exact data types remain unknown, it is not possible to quantify how many people face elevated exposure or which specific records are involved. The absence of confirmed counts does not eliminate the need for vigilance; it simply means the boundary of impact has not been publicly mapped.
For the organisation, a ransomware listing can bring operational disruption, regulatory notification obligations under health-privacy rules, reputational strain, and the costs of investigation and remediation. Those consequences depend on what actually occurred and on how the organisation responds—details that lie outside the limited public facts. The claim of exfiltration alone is sufficient to warrant attention from anyone who has been a patient or employee, without requiring speculation about unstated outcomes.
If your data was in this claimed breach
If you have been a patient, employee, or other associate of MNGI Digestive Health, treat the possibility of exposure seriously even while exact contents remain unconfirmed. Monitor financial and insurance statements for unfamiliar activity, be cautious of unsolicited contacts that reference medical or personal details, and consider placing fraud alerts or credit freezes if you believe sensitive identifiers may have been involved. Retain any official notices the practice may issue, as they can clarify next steps and available support.
You can also run a free exposure scan of your email address to check whether your information has already surfaced in known breach data sets. That check does not confirm or rule out inclusion in this specific incident, but it provides a practical way to see whether your credentials or personal details appear in previously compiled breach collections and to decide on further hardening of accounts and monitoring.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Viking Therapeutics Listed by alphv Ransomware GroupViking Therapeutics reported to the SEC following a breach Listed by alphv Ransomware GroupLeClair Group Listed by alphv Ransomware GroupHenry Schein Inc - Henry's " LOST SHINE " Listed by alphv Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the MNGI Digestive Health2 Listed by alphv Ransomware Group →
Publicly posted by alphv — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.