LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › yuagam Listed by qilin Ransomware Group

HIGH severityUnverified claimHow we verify

yuagam Listed by qilin Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·February 25, 2025
yuagam Listed by qilin Ransomware Group

Reported February 25, 2025.

HIGH
Severity
February 25, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

yuagam was listed by the qilin ransomware group on February 25, 2025, after internal files were exfiltrated in a ransomware attack. An undisclosed number of people may have been affected; individuals should check whether their information was involved and take protective steps.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

When a healthcare organisation appears on a ransomware group's leak site, the practical stakes for patients, staff and partners are immediate and personal. Medical records, contact details and administrative files can become tools for identity fraud, targeted phishing or privacy harm long after the initial intrusion. In the case of yuagam, publicly reported detail remains limited, yet the listing itself is enough to warrant careful attention from anyone who has interacted with the organisation.

On 25 February 2025, the ransomware group known as qilin listed yuagam among its claimed victims. The available information states that internal files were exfiltrated in a ransomware attack. The number of people affected has not been disclosed, and the precise contents of the material remain unconfirmed beyond the general description of internal files. This article sets out what is known, what is claimed, and what practical steps people can take.

What happened

According to public reporting dated 25 February 2025, yuagam was listed by the qilin ransomware group. The reported summary characterises the incident as a ransomware attack in which internal files were allegedly exfiltrated. No further technical details—such as the initial access method, the duration of the intrusion, the volume of data taken, or any ransom demand—have been made public in the material available for this account. The number of individuals whose information may be involved is listed as unknown.

Because the primary source of the claim is the group's own listing, the assertion that yuagam was compromised and that files were removed should be treated as an unverified claim until independently confirmed by the organisation or by competent authorities. No public confirmation of the full scope or of any subsequent data publication has been included in the facts provided here.

The group behind it: qilin

Qilin is a ransomware operation that has been active for several years and is widely documented in open-source threat reporting. Like many contemporary ransomware groups, it typically follows a double-extortion model: encrypting systems while also copying data, then threatening to publish or sell the stolen material if payment is not made. The group has operated as a ransomware-as-a-service platform, allowing affiliates to conduct intrusions under its brand and infrastructure.

Public analyses of prior qilin activity describe common tactics that include phishing, exploitation of exposed remote-access services, and the use of legitimate administrative tools once inside a network. The group has previously listed organisations across multiple sectors and countries on its leak site. In the present case, the only claim specifically tied to yuagam is the listing itself and the statement that internal files were exfiltrated; no additional statements attributed to qilin about this particular victim appear in the available facts.

About yuagam

Yuagam refers to the Yeditepe University Healthcare Institutions group. Public background indicates it was founded in 2005 under the aegis of the Istanbul Education and Culture Foundation (ISTEK) and Yeditepe University. It is described as one of the established multidisciplinary hospital groups operating in Turkey. Organisations of this type typically combine clinical care, teaching and research functions and therefore maintain extensive records relating to patients, staff, students, suppliers and institutional operations.

A breach affecting a healthcare provider carries particular weight because the data such institutions hold is both sensitive and long-lived. Even when the exact files involved remain undisclosed, the mere possibility that clinical or administrative material has left the organisation's control raises legitimate concern for the people whose information may be among those files.

The information in question

The facts name the exposed material only as “internal files exfiltrated in ransomware attack.” No more granular inventory—such as patient records, financial data, employee files or specific document categories—has been publicly detailed in the material used for this report. The number of people affected is likewise unknown.

Healthcare organisations of this kind ordinarily hold medical histories, diagnostic results, appointment and billing information, staff personnel records, and various operational documents. It is therefore reasonable to expect that some combination of these categories could be present among internal files. However, because the exact contents have not been confirmed, any assertion that particular data types were taken would be speculative. Readers should treat the scope as unconfirmed pending further official disclosure.

The real-world impact

For individuals, the principal risks are secondary misuse of personal information. Even limited internal files can contain names, contact details, identification numbers or medical references that enable phishing, social-engineering calls, or attempts at identity fraud. Medical information, if present, can also create privacy harms that are difficult to reverse. Because the scale of the incident is unknown, it is not possible to quantify how many people face elevated risk; the prudent assumption is that anyone who has been a patient, employee or close partner of the organisation should remain alert.

For the organisation itself, a ransomware incident typically disrupts clinical and administrative systems, imposes recovery costs, and can damage trust among patients and partners. Regulatory obligations around personal-data protection may also apply, depending on jurisdiction. None of these consequences have been quantified in the available facts, and no statement of organisational fault is made here; the focus remains on the practical exposure created by the claimed exfiltration of internal files.

Were you affected?

If you have been a patient, staff member or contractor of yuagam or the broader Yeditepe University Healthcare Institutions group, treat the listing as a reason to increase caution rather than as proof that your specific records were taken. Monitor bank and credit accounts for unexpected activity, be sceptical of unsolicited messages that reference medical appointments or personal details, and consider placing fraud alerts with relevant credit or identity-protection services where available. Change passwords on any accounts that reused credentials associated with the organisation, and enable multi-factor authentication wherever possible.

You can also run a free exposure scan of your email address to check whether that address has already appeared in known breach data sets. Such a scan will not confirm or rule out involvement in this specific incident, but it can indicate whether your email has surfaced elsewhere and help you prioritise further protective steps. Official updates from the organisation or from data-protection authorities, if and when they appear, remain the most reliable source of confirmation about the true scope of the event.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

Companyyuagam security record
87/100
DoxxScan™ · Low doxx risk
B 80Good record

1 reported incident on record.

See yuagam’s full breach history →

More recent breaches

Can Healthcare Group Listed by qilin Ransomware GroupJune 15, 2026KOPA Kozmetik A Listed by qilin Ransomware GroupDecember 31, 2025Georgia Dermatology & Skin Cancer Center Listed by qilin Ransomware GroupDecember 26, 2025Shore Gardens Rehabilitation & Nursing Center Listed by qilin Ransomware GroupDecember 24, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the yuagam Listed by qilin Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by qilin — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram