LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › MorseLife Health System, Inc. Listed by Booba Team Ransomware Group

HIGH severityUnverified claimHow we verify

MorseLife Health System, Inc. Listed by Booba Team Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·October 4, 2026
MorseLife Health System, Inc. Listed by Booba Team Ransomware Group

Reported October 4, 2026.

HIGH
Severity
October 4, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

MorseLife Health System, Inc. was listed by the Booba Team ransomware group on October 04, 2026; the group claims to have obtained data from the organisation, but the organisation has made no statement and the claim remains unverified. Individuals who may have received services from MorseLife Health System, Inc. should monitor accounts, watch for unusual activity, and contact the organisation directly for further information.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Booba Team, a ransomware and extortion group, has listed MorseLife Health System, Inc. on its leak site, according to a report dated October 04, 2026. The listing names the organisation and its website, www.morselife.org, and claims that 344 GB of data is involved. MorseLife Health System, Inc. has not publicly confirmed the claim as of writing. The number of people who might be affected is unknown, and the types of data the group says it holds have not been detailed in the available listing summary.

Because the claim comes only from an extortion crew’s leak site, it remains unverified. Listings of this kind are used to pressure organisations; they can be incomplete, recycled, exaggerated, or false. What follows treats the Booba Team entry as an allegation, explains what such a listing does and does not establish, and outlines conditional steps readers can take if they later learn their information was involved.

What the listing says

The public report states that MorseLife Health System, Inc. appears on a Booba Team leak-site listing. The organisation is described in the summary as operating in hospitals and health care, with the website www.morselife.org. The listing claims “stolen data” amounting to 344 GB. No further breakdown of file types, systems, or timelines is provided in the facts available for this article. How many individuals might be implicated is listed as unknown. Method of access, if any, is undisclosed. Whether any files have actually been published beyond the listing itself is not established in the material at hand.

In short, the known public detail is limited to the group’s claim that it listed the organisation, associated it with the health-care sector and that website, and asserted a 344 GB volume. Everything else about scope, content, and confirmation remains unconfirmed.

Inside Booba Team

Booba Team is known in public reporting as a ransomware and data-extortion actor that operates in the familiar double-extortion pattern used by many such crews: encrypt systems where it can, exfiltrate copies of data, and threaten to publish or sell material on a leak site if payment is not made. Groups in this category typically post victim names, sometimes with sample files or size claims, to increase pressure. Their leak-site entries are marketing and coercion tools, not audited inventories.

Public coverage of Booba Team has described it as following tactics common to the ransomware ecosystem—targeting organisations that hold sensitive operational or personal records, and using timed leak-site posts to force negotiation. None of that general pattern proves that any specific claim about MorseLife Health System, Inc. is accurate. For this incident, the only attributable statement is that the group has listed the organisation and claims 344 GB of data; no additional victim-specific assertions from the group are included in the facts provided here.

About MorseLife Health System, Inc.

MorseLife Health System, Inc. is identified in the listing context as a hospitals and health-care organisation, with a public web presence at www.morselife.org. Organisations in this sector typically deliver clinical care, long-term or senior services, rehabilitation, or related support, and they sit at the centre of patients’ medical and administrative records. A leak-site claim against a named health system matters because the sector routinely handles information that, if misused, can affect privacy, identity security, and trust in care relationships—even when the claim itself has not been confirmed by the organisation or by regulators.

A listing does not by itself establish that systems were compromised, that records left the organisation, or that any particular patient or employee was affected. It does establish that an extortion group has chosen to name the organisation in public, which can create uncertainty for patients, families, staff, and partners until official channels clarify the situation.

The information in question

The available facts state that data types named as exposed are not disclosed. The listing summary asserts a volume of 344 GB but does not inventory contents. Therefore no specific categories—such as clinical notes, billing files, insurance identifiers, or employee records—can be stated as fact for this case.

If files from a health system were ever taken, organisations of this kind typically hold combinations of demographic data, contact details, medical history, treatment and medication information, insurance and billing records, and sometimes Social Security numbers or government identifiers used for eligibility and payment. They may also hold workforce data. That is a description of sector norms, not a confirmation of what, if anything, Booba Team holds. The exact contents tied to this listing remain unconfirmed.

The real-world impact

For individuals, the practical risk is conditional. If personal or medical information related to them were later shown to have been copied and circulated, possible harms include targeted phishing that references real appointments or conditions, attempts at medical identity fraud, financial fraud using stolen identifiers, and long-term privacy exposure that is difficult to reverse. Health-related data can be especially sensitive because it is hard to change and can be used to craft convincing scams.

For the organisation, an unverified leak-site listing can still drive operational cost: internal investigation, legal and regulatory inquiry, patient and partner communication, and reputational strain—whether or not the group’s volume claim proves accurate. A listing alone does not prove negligence, successful intrusion, or data publication; it proves only that a named group has made a public allegation. Until MorseLife Health System, Inc. or an authoritative body confirms or denies the claim, the scale of any real-world exposure stays unknown.

If your data was involved

If you are a patient, family member, or employee and you later receive official notice—or if independent reporting confirms involvement—treat the situation as a potential exposure rather than assuming every detail on a leak site is true. Practical first steps include monitoring bank and insurance statements for unfamiliar activity; being cautious with unexpected calls or emails that cite medical details; considering a fraud alert or credit freeze where appropriate in your country; and using unique passwords with multi-factor authentication on health-portal and email accounts. Do not assume your records are in the claimed 344 GB set unless a credible source says so.

You can also run a free exposure scan of your email address to check whether that address has already appeared in other known breach datasets, which can help you prioritise password changes and monitoring even while this particular listing remains unconfirmed.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

SourceLeak-site claim data adapted from RansomLook.io, used under CC BY 4.0.

CompanyMorseLife Health System, Inc. security record
84/100
DoxxScan™ · Low doxx risk
B- 76Above-average record

1 reported incident on record.

See MorseLife Health System, Inc.’s full breach history →
RelatedMore incidents at MorseLife Health System, Inc.

More recent breaches

EdgeEndo® USA Listed by Booba Team Ransomware GroupOctober 2, 2026Soni Medical Centre Listed by Booba Team Ransomware GroupOctober 2, 2026University of Illinois Chicago Listed by Booba Team Ransomware GroupOctober 2, 2026Raleigh Family Medicine Listed by Booba Team Ransomware GroupOctober 2, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the MorseLife Health System, Inc. Listed by Booba Team Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by boobateam — unverified claim, pending independent verification. Leak-site claim data adapted from RansomLook.io, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram