Rumah Sakit Universitas Indonesia (RSUI) Listed by nova Ransomware Group: What Was Exposed & What To Do
Rumah Sakit Universitas Indonesia (RSUI) was listed by the nova ransomware group on July 20, 2026, with internal files reported as exfiltrated. Anyone connected to the hospital should check whether their information was exposed and take appropriate protective steps.
Rumah Sakit Universitas Indonesia (RSUI) has been listed by the nova ransomware group, according to a report dated 20 July 2026. Public detail so far is limited: the listing asserts that internal files were exfiltrated in a ransomware attack, that medical data from a drive is at risk, and that the group has offered a file tree and samples to the organisation if it contacts the group’s support channel. The number of people affected remains unknown, and independent confirmation of the claim has not been made public.
For patients, staff, students and research partners connected to Indonesia’s leading university teaching hospital, any credible claim of internal-file theft raises immediate questions about the confidentiality of medical and administrative records. What follows sets out only what is known, what is claimed, and what practical steps affected individuals can take.
Breaking down the breach
On 20 July 2026, RSUI appeared on the leak site associated with the nova ransomware group. The available summary states that internal files were exfiltrated during a ransomware attack and that medical data held on a drive is at risk. Nova is reported to have indicated it will supply a directory tree and sample files once the organisation contacts its support department. No public figure has been given for the volume of data, the precise date of intrusion, the initial access method, or whether encryption of systems also occurred. The number of individuals whose information may be involved is listed as unknown. All of these operational details therefore remain undisclosed.
Who is nova?
Nova is a ransomware operation that follows the now-common double-extortion model: after gaining access to a network, operators exfiltrate data and then threaten to publish it unless a ransom is paid. Like other groups in this category, nova typically posts victim names on a dedicated leak site, sometimes accompanied by file listings or limited samples, to increase pressure. Public reporting on nova has described the use of standard ransomware toolsets, affiliate-style recruitment, and negotiation channels presented as “support.” None of these general patterns constitute proof of the specific technical steps taken against RSUI; the group’s listing of the hospital should be treated as an unverified claim unless and until the organisation or independent investigators confirm it.
Rumah Sakit Universitas Indonesia (RSUI) and its sector
RSUI is the teaching hospital of the University of Indonesia. It delivers advanced clinical care, trains medical students and residents, and supports clinical research. Hospitals of this type routinely hold large volumes of sensitive information: patient demographics and medical histories, diagnostic images and laboratory results, staff and student records, research datasets, and administrative and financial files. Because the institution sits at the intersection of healthcare, higher education and research, a breach can affect not only individual patients but also clinical trials, academic collaborations and the wider public-health infrastructure in Indonesia. The sensitivity of medical data makes any confirmed exposure especially consequential under both Indonesian data-protection expectations and international norms governing health information.
What was likely exposed
The facts name only “internal files exfiltrated in a ransomware attack” and state that medical data from a drive is at risk. Exact data types, file counts and whether patient, staff or research records were included have not been publicly confirmed. Organisations of this kind typically maintain:
- Patient clinical records, appointment histories and billing information
- Staff and student personnel files and credentials
- Research protocols, datasets and ethics documentation
- Internal administrative, financial and operational documents
Until RSUI or independent analysis releases a verified inventory, any assertion about specific contents beyond the general claim of internal and medical-related files remains unconfirmed.
The real-world impact
If medical or personal data were among the exfiltrated files, affected individuals could face risks of identity misuse, targeted phishing, or embarrassment from the exposure of health conditions. For the hospital, the consequences may include operational disruption, regulatory scrutiny, loss of patient trust, and the cost of forensic investigation and notification. Because the scale is unknown, it is not yet possible to quantify how many people or which categories of record are involved. Even an unconfirmed listing can generate anxiety and prompt defensive steps by patients and staff; confirmed exposure would require more formal notification and support measures.
If your data was in this breach
If you have been a patient, employee, student or research participant at RSUI, treat the situation cautiously until official confirmation is issued. Monitor financial and medical account statements for unfamiliar activity, enable multi-factor authentication on email and patient-portal accounts, and be alert to phishing messages that reference the hospital or claim to offer breach-related assistance. Consider placing fraud alerts with relevant credit or identity services if you believe highly sensitive identifiers may have been involved. You can also run a free exposure scan of your email address to check whether your information has already surfaced in known breach datasets. Official updates should be sought directly from RSUI rather than from unverified third-party posts.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Koplarla Listed by nova Ransomware GroupKoperasi Karyawan PT Aplikanusa Lintasarta Listed by nova Ransomware GroupDigital Edge Listed by nova Ransomware GroupCanal 9 Litoral Listed by nova Ransomware GroupLatest breaches
Publicly posted by nova — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.