moph.gov.lb Listed by funksec Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
moph.gov.lb was listed by the funksec ransomware group on December 30, 2024, after internal files were exfiltrated in an attack. Individuals whose data may have been held by the site should check the group’s claims and review their own records for any signs of exposure.
When a government health ministry appears on a ransomware group's leak site, the immediate concern is not abstract cybersecurity jargon but the personal information of patients, staff, and residents that such an organisation routinely holds. On 30 December 2024, the Lebanese Ministry of Public Health domain moph.gov.lb was listed by the funksec ransomware group, which claims to have exfiltrated internal files in a ransomware attack. The number of people affected remains unknown, and public detail on the precise contents of those files is limited, yet the listing alone raises practical questions for anyone who has interacted with Lebanon's public-health system.
Because ministries of this kind manage health records, licensing data, and administrative files, even a partial exposure can create lasting risks of identity misuse, targeted fraud, or secondary attacks. This article sets out only what has been reported, places the claim in context, and outlines concrete steps for those who may be affected.
Inside the incident
Public reporting states that moph.gov.lb was listed by the funksec ransomware group on 30 December 2024. The group claims the listing follows a ransomware attack in which internal files were exfiltrated. No confirmed figure for the number of people affected has been released, and the exact date of the intrusion, the method of initial access, and the volume of data taken remain undisclosed. The available information consists solely of the leak-site listing itself and the characterisation of the material as internal files obtained during a ransomware incident. No independent verification of the claim, no ransom demand details, and no confirmation of data publication have been provided in the reported facts.
Who is funksec?
Funksec is a ransomware operation that has appeared in public threat-intelligence reporting as a group employing double-extortion tactics: encrypting systems while also copying data and threatening to release it if payment is not made. Like many contemporary ransomware crews, it maintains a leak site on which it posts victim names and, at times, sample files to pressure organisations. Public documentation of funksec describes typical activity that includes opportunistic targeting of organisations across sectors, use of commodity and custom tools for lateral movement, and the publication of claims rather than always verified dumps. The listing of moph.gov.lb is therefore best understood as a claim made by the group; the facts do not establish that the data has been confirmed as stolen or released beyond the group's own assertion.
Who is moph.gov.lb?
moph.gov.lb is the online presence of the Ministry of Public Health of Lebanon, the governmental body responsible for public-health policy, healthcare regulation, and the oversight of hospitals, clinics, and national health programmes. Such ministries typically maintain records related to patient care, medical licensing, pharmaceutical regulation, vaccination programmes, and administrative personnel. A breach affecting a national health authority is consequential because the data it holds often includes sensitive medical and personal identifiers that cannot easily be changed, and because disruption of ministry systems can affect service delivery and public trust. The facts do not allege any specific security failure by the ministry; they simply record the group's claim that the organisation was targeted.
The information in question
The reported facts state only that internal files were exfiltrated in a ransomware attack. No further breakdown of file types, databases, or individual data fields has been disclosed. Organisations of this kind commonly hold medical records, staff directories, correspondence, procurement documents, and regulatory filings. Because the precise contents remain unconfirmed, it is not possible to state as fact which categories of personal or sensitive information, if any, were taken. Readers should treat any specific claims about patient lists, national ID numbers, or financial data as unverified unless independently corroborated.
What's at stake
For individuals, the primary risks are long-term rather than immediate. Health-related data can be used for targeted phishing, insurance fraud, or identity theft that is difficult to reverse. Staff whose contact or employment details appear in internal files may face social-engineering attempts. For the ministry itself, the stakes include potential operational disruption, the cost of incident response and system restoration, and the erosion of public confidence in the confidentiality of health services. Because the number of affected people is unknown and the data types are described only as internal files, the full scope of harm cannot yet be quantified; the practical consequence is that anyone who has supplied personal or medical information to Lebanese public-health services should treat the possibility of exposure as real until clearer information emerges.
If your data was in this claimed breach
Begin by treating unsolicited communications that reference health services or personal details with caution; verify any request through official ministry channels rather than links or numbers supplied in messages. Monitor financial and government accounts for unusual activity and consider placing fraud alerts with relevant credit or identity-protection services where available. Change passwords on accounts that reuse credentials associated with ministry portals, and enable multi-factor authentication wherever it is offered. Because the exact data set remains unconfirmed, a free exposure scan of your email address against known breach corpora can indicate whether that address has already appeared in other public dumps and help you prioritise further monitoring. Keep records of any suspicious contacts and report confirmed identity misuse to local authorities and the ministry's designated incident channels when they become available.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
moh.gov.vn Listed by funksec Ransomware Groupdealplexus.com Listed by funksec Ransomware Groupgervetusa.com Listed by funksec Ransomware Groupgervetusa.com Breach Listed by funksec Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the moph.gov.lb Listed by funksec Ransomware Group →
Publicly posted by funksec — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.