LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Taiwan - Mackay Hospital Listed by babuk2 Ransomware Group

HIGH severityUnverified claimHow we verify

Taiwan - Mackay Hospital Listed by babuk2 Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·February 6, 2025
Taiwan - Mackay Hospital Listed by babuk2 Ransomware Group

Reported February 6, 2025.

HIGH
Severity
February 6, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Taiwan’s Mackay Hospital was listed by the babuk2 ransomware group on February 6, 2025, with internal files reported stolen. Individuals who may have records with the hospital should review their accounts and consider protective steps.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

On 6 February 2025, the ransomware group known as babuk2 listed Taiwan - Mackay Hospital on its leak site, claiming to have carried out an attack that involved the exfiltration of internal files. For patients, staff and anyone whose records may sit inside a hospital’s systems, the practical stakes are immediate: personal and medical information, once removed from controlled networks, can be used for fraud, identity misuse or further targeting long after the initial incident. Public detail remains limited, and the number of people affected is unknown, yet the listing alone is enough to warrant careful attention from those connected to the organisation.

This article sets out only what has been reported, places the claim in the context of how such groups operate, and outlines the concrete risks and first steps available to individuals who may be involved.

Breaking down the breach

According to the available record, Taiwan - Mackay Hospital was listed by the babuk2 ransomware group on 6 February 2025. The group asserts that internal files were exfiltrated during a ransomware attack. No further technical details—such as the precise date of intrusion, the method of initial access, the volume of data taken, or any ransom demand—have been disclosed in the public summary. The number of people whose information may be involved is listed as unknown. The incident is therefore known only through the group’s own claim on its leak site; independent confirmation of the scale or success of the attack has not been provided in the facts available.

Ransomware operations of this type typically combine encryption of systems with the theft of data, followed by threats to publish the material if payment is not made. In this case the public record states only that internal files were exfiltrated and that the hospital was subsequently listed. No additional claims about specific systems compromised or files released have been recorded.

Inside babuk2

Babuk2 is associated with the broader Babuk ransomware family that first became widely known in 2021. The original Babuk operators specialised in double-extortion attacks: they encrypted victim networks while simultaneously stealing data and threatening to leak it on a dedicated site if the ransom was unpaid. Their source code was later leaked, enabling other actors to create variants that continue to use similar tactics. Groups operating under the Babuk or Babuk2 name have historically targeted organisations across multiple sectors, posting victim names and sample data on leak sites to increase pressure.

Public reporting on these actors emphasises that listings are claims made by the group itself and are not automatically verified. The groups typically demand payment in cryptocurrency, set short deadlines, and gradually release larger volumes of data when negotiations stall. No statements attributed to babuk2 beyond the listing of Taiwan - Mackay Hospital and the assertion of internal-file exfiltration are included in the facts of this incident; any further characterisation of their specific demands or actions against this hospital would be unsupported.

About Taiwan - Mackay Hospital

Taiwan - Mackay Hospital is a healthcare institution operating in Taiwan. Hospitals of this kind deliver medical care, maintain patient records, manage staff and administrative systems, and handle billing and insurance information. As a medical provider, the organisation necessarily processes large volumes of sensitive personal data, including health histories, contact details and identifiers required for treatment and compliance.

A breach affecting a hospital is consequential because the data it holds is both intimate and long-lived. Medical records cannot be changed like a password, and their exposure can affect an individual’s privacy, insurance standing and personal safety for years. Operational disruption inside a hospital can also delay care for current patients, though no such impact has been confirmed in the public facts of this case. The listing by babuk2 therefore raises concerns that extend beyond pure information security into the reliability of healthcare services and the protection of vulnerable individuals.

What data was at risk

The facts state that internal files were exfiltrated in the ransomware attack. No more granular inventory—such as patient names, medical diagnoses, financial records, staff credentials or specific document types—has been disclosed. The exact contents of the taken material therefore remain unconfirmed.

Organisations in the hospital sector typically hold electronic health records, appointment and treatment histories, laboratory results, insurance and billing data, employee personnel files, and internal administrative documents. Any of these categories could fall under the broad description of “internal files.” Because the public record does not name specific data types beyond that phrase, it is not possible to state with certainty what was taken. Readers should treat the exposure as potentially including sensitive personal and medical information while recognising that the precise scope is still unknown.

What's at stake

For individuals whose data may have been among the exfiltrated files, the primary risks are identity theft, medical fraud and targeted phishing. Stolen health information can be used to open fraudulent accounts, submit false insurance claims, or craft convincing social-engineering messages that reference real medical details. Because medical data is permanent, the window of risk does not close quickly. Staff members face parallel exposure of personal identifiers and employment records that could be leveraged for further attacks.

For the hospital itself, the stakes include possible operational disruption, regulatory scrutiny under Taiwan’s personal-data-protection rules, reputational damage, and the cost of investigation and remediation. Even when systems are restored, the knowledge that internal files left the network can erode patient trust. None of these outcomes has been confirmed as having occurred; they represent the ordinary consequences that follow a claimed ransomware exfiltration of this kind.

If your data was in this claimed breach

If you are a patient, former patient or employee of Taiwan - Mackay Hospital, treat the listing as a signal to increase vigilance rather than as proof that your specific records were taken. Begin by monitoring bank and credit-card statements for unfamiliar activity and consider placing a fraud alert or credit freeze with the relevant Taiwanese credit agencies if you hold local financial accounts. Change passwords on any accounts that reuse credentials you may have shared with the hospital, and enable multi-factor authentication wherever it is offered. Be alert to unexpected emails or calls that reference medical appointments or personal details; such messages may be phishing attempts built on stolen data.

You can also run a free exposure scan of your email address to check whether that address has already appeared in known breach datasets. Keep records of any suspicious contacts and report confirmed fraud to local authorities and the hospital’s data-protection contact if one is published. Public information about this incident remains limited; further official statements from the hospital or regulators, if they appear, should be the primary source for updates.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyMackay Hospital security record
87/100
DoxxScan™ · Low doxx risk
B 80Good record

1 reported incident on record.

See Mackay Hospital’s full breach history →
RelatedMore incidents at Mackay Hospital

More recent breaches

cch.org.tw - Changhua Christian Hospital Listed by babuk2 Ransomware GroupMarch 13, 2025kfar hatta medical center - Lebanon Listed by babuk2 Ransomware GroupApril 3, 2025theeyeclinicsurgicenter.com - The Eye Clinic Surgicenter company Listed by babuk2 Ransomware GroupMarch 29, 2025icvc.co - Instituto Cardiovascular del Cesar Listed by babuk2 Ransomware GroupMarch 29, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the Taiwan - Mackay Hospital Listed by babuk2 Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by babuk2 — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram