MorseLife Health System, Inc. Listed by Booba Team Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
MorseLife Health System, Inc. was listed by the Booba Team ransomware group on October 04, 2026; the group claims to have obtained data from the organisation, but the organisation has made no statement and the claim remains unverified. Individuals who may have received services from MorseLife Health System, Inc. should monitor accounts, watch for unusual activity, and contact the organisation directly for further information.
Booba Team, a ransomware and extortion group, has listed MorseLife Health System, Inc. on its leak site, according to a report dated October 04, 2026. The listing names the organisation and its website, www.morselife.org, and claims that 344 GB of data is involved. MorseLife Health System, Inc. has not publicly confirmed the claim as of writing. The number of people who might be affected is unknown, and the types of data the group says it holds have not been detailed in the available listing summary.
Because the claim comes only from an extortion crew’s leak site, it remains unverified. Listings of this kind are used to pressure organisations; they can be incomplete, recycled, exaggerated, or false. What follows treats the Booba Team entry as an allegation, explains what such a listing does and does not establish, and outlines conditional steps readers can take if they later learn their information was involved.
What the listing says
The public report states that MorseLife Health System, Inc. appears on a Booba Team leak-site listing. The organisation is described in the summary as operating in hospitals and health care, with the website www.morselife.org. The listing claims “stolen data” amounting to 344 GB. No further breakdown of file types, systems, or timelines is provided in the facts available for this article. How many individuals might be implicated is listed as unknown. Method of access, if any, is undisclosed. Whether any files have actually been published beyond the listing itself is not established in the material at hand.
In short, the known public detail is limited to the group’s claim that it listed the organisation, associated it with the health-care sector and that website, and asserted a 344 GB volume. Everything else about scope, content, and confirmation remains unconfirmed.
Inside Booba Team
Booba Team is known in public reporting as a ransomware and data-extortion actor that operates in the familiar double-extortion pattern used by many such crews: encrypt systems where it can, exfiltrate copies of data, and threaten to publish or sell material on a leak site if payment is not made. Groups in this category typically post victim names, sometimes with sample files or size claims, to increase pressure. Their leak-site entries are marketing and coercion tools, not audited inventories.
Public coverage of Booba Team has described it as following tactics common to the ransomware ecosystem—targeting organisations that hold sensitive operational or personal records, and using timed leak-site posts to force negotiation. None of that general pattern proves that any specific claim about MorseLife Health System, Inc. is accurate. For this incident, the only attributable statement is that the group has listed the organisation and claims 344 GB of data; no additional victim-specific assertions from the group are included in the facts provided here.
About MorseLife Health System, Inc.
MorseLife Health System, Inc. is identified in the listing context as a hospitals and health-care organisation, with a public web presence at www.morselife.org. Organisations in this sector typically deliver clinical care, long-term or senior services, rehabilitation, or related support, and they sit at the centre of patients’ medical and administrative records. A leak-site claim against a named health system matters because the sector routinely handles information that, if misused, can affect privacy, identity security, and trust in care relationships—even when the claim itself has not been confirmed by the organisation or by regulators.
A listing does not by itself establish that systems were compromised, that records left the organisation, or that any particular patient or employee was affected. It does establish that an extortion group has chosen to name the organisation in public, which can create uncertainty for patients, families, staff, and partners until official channels clarify the situation.
The information in question
The available facts state that data types named as exposed are not disclosed. The listing summary asserts a volume of 344 GB but does not inventory contents. Therefore no specific categories—such as clinical notes, billing files, insurance identifiers, or employee records—can be stated as fact for this case.
If files from a health system were ever taken, organisations of this kind typically hold combinations of demographic data, contact details, medical history, treatment and medication information, insurance and billing records, and sometimes Social Security numbers or government identifiers used for eligibility and payment. They may also hold workforce data. That is a description of sector norms, not a confirmation of what, if anything, Booba Team holds. The exact contents tied to this listing remain unconfirmed.
The real-world impact
For individuals, the practical risk is conditional. If personal or medical information related to them were later shown to have been copied and circulated, possible harms include targeted phishing that references real appointments or conditions, attempts at medical identity fraud, financial fraud using stolen identifiers, and long-term privacy exposure that is difficult to reverse. Health-related data can be especially sensitive because it is hard to change and can be used to craft convincing scams.
For the organisation, an unverified leak-site listing can still drive operational cost: internal investigation, legal and regulatory inquiry, patient and partner communication, and reputational strain—whether or not the group’s volume claim proves accurate. A listing alone does not prove negligence, successful intrusion, or data publication; it proves only that a named group has made a public allegation. Until MorseLife Health System, Inc. or an authoritative body confirms or denies the claim, the scale of any real-world exposure stays unknown.
If your data was involved
If you are a patient, family member, or employee and you later receive official notice—or if independent reporting confirms involvement—treat the situation as a potential exposure rather than assuming every detail on a leak site is true. Practical first steps include monitoring bank and insurance statements for unfamiliar activity; being cautious with unexpected calls or emails that cite medical details; considering a fraud alert or credit freeze where appropriate in your country; and using unique passwords with multi-factor authentication on health-portal and email accounts. Do not assume your records are in the claimed 344 GB set unless a credible source says so.
You can also run a free exposure scan of your email address to check whether that address has already appeared in other known breach datasets, which can help you prioritise password changes and monitoring even while this particular listing remains unconfirmed.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
SourceLeak-site claim data adapted from RansomLook.io, used under CC BY 4.0.
More recent breaches
EdgeEndo® USA Listed by Booba Team Ransomware GroupSoni Medical Centre Listed by Booba Team Ransomware GroupUniversity of Illinois Chicago Listed by Booba Team Ransomware GroupRaleigh Family Medicine Listed by Booba Team Ransomware GroupLatest breaches
Publicly posted by boobateam — unverified claim, pending independent verification. Leak-site claim data adapted from RansomLook.io, used under CC BY 4.0.
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.