LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Southwest Healthcare Services Listed by donutleaks Ransomware Group

HIGH severityUnverified claimHow we verify

Southwest Healthcare Services Listed by donutleaks Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·October 22, 2022
Southwest Healthcare Services Listed by donutleaks Ransomware Group

Reported October 22, 2022.

HIGH
Severity
October 22, 2022
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The Southwest Healthcare Services Listed by donutleaks Ransomware Group (reported October 22, 2022) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Ransomware groups continue to target healthcare and community providers, listing victims on leak sites and claiming to have stolen internal files as leverage. In that landscape, smaller regional organisations can face the same pressure as larger systems, with limited public detail often leaving patients and staff unsure what was taken.

On October 22, 2022, Southwest Healthcare Services was listed by the ransomware group donutleaks. Public reporting describes the incident as a ransomware attack in which internal files were allegedly exfiltrated. The number of people affected remains unknown, and independent confirmation of the group’s claims has not been detailed in the available record. For a non-profit serving rural communities in southwest North Dakota and northwest South Dakota, any exposure of internal material raises practical concerns about privacy, operations, and trust.

Breaking down the breach

According to the public listing associated with the incident, Southwest Healthcare Services appeared on donutleaks’ leak site on or around October 22, 2022. The reported summary characterises the event as a ransomware attack involving exfiltration of internal files and references a full data download. No figure for individuals affected has been published in the material available for this account. Timing of the underlying intrusion, the initial access method, whether systems were encrypted, and any negotiation or recovery timeline are not disclosed in the facts at hand. The listing itself should be treated as a claim by the group rather than as independently verified detail unless further confirmation emerges.

What is stated is limited: the organisation was named, the attack type is described as ransomware with internal files taken, and the report date is October 22, 2022. Beyond that, scale, exact file inventory, and confirmation status remain undisclosed.

Who is donutleaks?

Donutleaks is known publicly as a ransomware operation that publishes victim names on a leak site and claims to hold stolen data, a pattern common among groups that combine encryption pressure with the threat of data release. Such actors typically advertise “full data” packages and set deadlines to coerce payment, though the accuracy of any single listing varies and is not automatically proven by appearance on a site. Notable prior activity attributed to the group in open reporting follows the same leak-site model used by other ransomware brands: name the organisation, assert exfiltration, and offer downloads or samples. For this incident, the only specific assertion tied to Southwest Healthcare Services in the given facts is the listing and the claim of internal files exfiltrated in a ransomware attack; no further quotes or unique demands from the group about this victim are provided here.

Southwest Healthcare Services and its sector

Southwest Healthcare Services is described as a non-profit organisation dedicated to providing quality healthcare in southwest North Dakota and northwest South Dakota. Organisations of this kind typically operate clinics, hospitals, or related community health services in sparsely populated regions, where they may be among the primary local sources of care. The healthcare sector as a whole holds clinical, administrative, and operational records and has been a frequent target for ransomware because continuity of care and regulatory obligations increase the cost of disruption.

A breach affecting a regional non-profit matters because patients, employees, and partners often have long-standing relationships with a single local provider. Even when public detail is thin, the combination of sensitive workflows and limited alternative providers in rural areas makes any credible claim of data theft consequential for the community the organisation serves.

What was likely exposed

The facts name the exposed material only as internal files exfiltrated in a ransomware attack. No inventory of record types, no patient or employee counts, and no sample file categories are given. Exact contents are therefore unconfirmed.

Organisations in this sector commonly hold, in the normal course of business, information such as patient demographics and clinical documentation, billing and insurance data, employee records, vendor contracts, and internal operational documents. That is general sector context, not a statement of what was taken in this case. Until Southwest Healthcare Services or a regulator publishes a verified description, it is not possible to say which of those categories—if any—were among the files the group claims to hold.

Why it matters

For individuals, the real-world risk depends on what was actually in the stolen files. If personal or health-related data were included, possible outcomes include unwanted contact, attempts at fraud or identity misuse, and anxiety about privacy. If only administrative or operational documents were involved, the direct personal risk may be lower, though reputational and contractual harm to the organisation can still affect service delivery. Because the number of people affected and the precise data types are unknown, anyone who has been a patient, employee, or close partner of the organisation has reason to stay alert without assuming the worst.

For the organisation, a ransomware incident with claimed exfiltration can mean operational interruption, recovery costs, notification and regulatory duties, and lasting questions from the communities it serves. None of that establishes negligence as fact; it simply describes the pressures that follow when a healthcare provider is named in this way.

Were you affected?

If you have a relationship with Southwest Healthcare Services—as a patient, staff member, or vendor—monitor official notices from the organisation and from relevant regulators for any confirmation of what was involved and who must be notified. Watch financial and insurance statements for unfamiliar activity, and be cautious of unexpected messages that reference the incident or urge urgent action. Consider placing fraud alerts with major credit bureaus if you later learn that identity-related data was involved. You can also run a free exposure scan of your email address to check whether your information has already appeared in known breach datasets, which may help you decide what further steps to take while public detail on this incident remains limited.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanySouthwest Healthcare Services security record
88/100
DoxxScan™ · Low doxx risk
B 83Good record

1 reported incident on record.

See Southwest Healthcare Services’s full breach history →

More recent breaches

Health Care Solutions Group Listed by donutleaks Ransomware GroupOctober 1, 2022Pittsburgh’s Trusted Orthopaedic Surgeons Listed by donutleaks Ransomware GroupAugust 10, 2025labline.it Listed by donutleaks Ransomware GroupJuly 17, 2024Watsonclinic.com Listed by donutleaks Ransomware GroupMarch 9, 2024

Latest breaches

Read GalaxyWarden’s full analysis of the Southwest Healthcare Services Listed by donutleaks Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by donutleaks — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram