-
A hacker claims they broke in and stole 3.7 GB of user data from French cancer treatment support platform Jinko.
-
The stolen data may include 3,552 accounts and over 20,000 messages, as well as 2,626 files.
-
Some stolen records contain cancer details, treatment history and care data. The full scope is still under review.

A French service that helps cancer patients has reportedly suffered a cyberattack that exposed user data and some health data.
According to reports, Jinko confirmed the attack on September 7, after a hacker posted an archive on a cybercrime forum the day before. The company’s co-founder told Clubic that someone gained access to its systems and took user data. Some users also had health and care data exposed.
The hacker claims the archive holds about 3.7 GB of data from Jinko.care. It reportedly has 85 Firestore tables, more than 883,000 rows, and 2,626 files.
The attack is now confirmed. But the full list of stolen data still comes from the hacker’s claim and Jinko’s first response.
What the Hacker Claims to Have Stolen
According to the leak post, the data encompasses about 3,552 user accounts. This includes users’ names, dates of birth, emails, phone numbers, and home addresses.
In addition, the assertion also involves doctors and health professionals in terms of their name, field of profession, and their contact information.
The privacy policy of Jinko shows that this kind of data is processed by its service. Jinko states that it collects names, emails, phone numbers, date of birth, home address, and work information.
It also says its service handles health data. This includes cancer type, the date of diagnosis, the stage of care, care site and doctors.
Cancer and Treatment Data May Be Exposed
The most serious part of the attack is the health data. The stolen data may include cancer types, disease stages, tumors that spread, cancer return, and past or current care. It may also include hormone care, drugs, surgery history, family history and symptoms.
The report also lists weight records, quality-of-life forms and care notes. The data may cover breast, lung, gut and gynecologic cancers. It may also cover people at many points in care, from a new diagnosis to care and remission.
Jinko’s own statement matters here. The company told Clubic that some users had health and care data exposed. That backs up the claim that the attack involved very private health data. Still, Jinko has not said that every field in the hacker’s list was stolen.
More than 20,000 Messages and Over 2,600 Files in the Theft Claim
The claimed archive also has a large set of private chats. The attack may have exposed over 20,000 messages spanning more than 1,000 chat conversations as well as hundreds of chats with an AI chatbot, based on the hacker’s claims.
The archive may include posts, comments, replies and likes from a user group. If the data is real, these records could show what patients shared during care. They could also show chats with health workers.
The hacker also says the archive has 2,626 files from Jinko’s storage system. The files may include PDFs, images, audio, and video. Some may hold medical papers, care files, forms and other patient records.
The leak report also says some files relate to health workers and care services. But Jinko has not confirmed the file count or each file type.
Jinko Says It Secured Its Systems
Jinko told Clubic that it opened an inquiry soon after it found the attack. The company says it secured its systems and told people who may be affected.
Jinko also says it is working with the right authorities and plans to file a police report. The company apologized to users. It’s still not clear exactly how the hacker pulled off the attack, whether they used stolen logins, a bug, a cloud error or another path.
Why this Breach Matters
This attack is more serious than a leak of names and email addresses. Health data can reveal very private facts about a person. In this case, the claimed data could link a person’s name to cancer, care, symptoms and treatment.
A message that names a real doctor, drug or visit may look real. People who use Jinko should be wary of odd calls, emails or texts that mention their health, care, doctor or Jinko account.
The pattern of attacks on healthcare providers extends well beyond France. Ransomware groups have targeted U.S. senior care facilities with similar consequences, the Qilin group claimed responsibility for the Covenant Health breach, which affected almost 480,000 patients and residents in Maine and New Hampshire.
The Full Scope of the Attack Remains a Mystery
The key fact changed after the first data leak report. Jinko has since confirmed an attack, an unauthorized entry and the theft of user data. It also confirmed that some users had health and care data exposed.
The reported 3.7 GB size, 3,552 accounts, 20,635 messages, and 2,626 files still come from the claimed stolen data. Jinko has not publicly confirmed each figure.
The same is true for the 883,000-plus rows and 85 Firestore tables. For now, we only know that Jinko suffered a cyberattack and the attacker stole user data, including some health records. The full amount and type of data lost are still under review.