Search TorNews

Find cybersecurity news, guides, and research articles

Popular searches:

Home » News » Data Breaches » Termite Ransomware Claims Affinia Healthcare Breach, Publishes Alleged Patient Data

Termite Ransomware Claims Affinia Healthcare Breach, Publishes Alleged Patient Data

By:
Last updated:July 28, 2026
Human Written
  • The Termite Ransomware Group has claimed responsibility for attacking the Affinia Healthcare system and made some samples of these files available to prove its claims.

  • These claimed samples included health-related, financial, clinical records, and identity documents.

  • Affinia Healthcare hasn’t reported any data breach when the Termite claim appeared on July 28, 2026.

Termite Ransomware Claims Affinia Healthcare Breach, Publishes Alleged Patient Data

The Termite ransomware group has added the US healthcare provider, Affinia Healthcare, as its recent victim. The group reportedly published sample documents that it says were taken from the organization’s systems.

This includes patient records and financial data. This information might include patient medical records, financial data, clinical communications, diagnostic results, and identification information. It is, however, not certain whether the hack is indeed true because Affinia Healthcare has not confirmed any hack incident.

What Termite Claims to have Taken

According to the threat actor’s alleged leaked materials, the exposed information may include several sensitive categories. This reportedly includes patient medical files, clinical correspondences, and diagnostic reports. Assuming this is true, then it might be possible to obtain some sensitive information regarding health matters.

The group also allegedly shared financial records and identity documents. These materials may create risks beyond medical privacy. Identity documents can be useful to criminals carrying out identity theft or targeted scams. Financial information may also increase the risk of fraud.

However, the existence of sample files does not prove the full size of a breach. The ransomware threat also does not prove that each document is up-to-date or that all documents were obtained from Affinia Healthcare itself.

Ransomware operators use the samples to force victims into making payments. However, the samples do not necessarily tell the whole story.

Who Is the Termite Ransomware Group?

Termite’s first recognition as a ransomware group was in late 2024 when the operators claimed attacks associated with the exploitation of Cleo file transfer solutions. Security researchers identified multiple victims across several industries during their early activity.

Termite is also infamous for using data theft as a source of pressure. During these attacks, criminals sometimes make copies of files before they lock down a system. If the victim won’t play along, the attackers threaten to leak the stolen information.

This tactic, called double extortion, means they’re not just asking for money to unlock your files. They also want cash to keep your sensitive data from going public.

Termite previously claimed responsibility for attacks involving major organizations. One such claim happened in 2024 when they boasted about stealing hundreds of gigabytes of data from Blue Yonder.

The group has also appeared in claims involving healthcare organizations. A February 2026 report linked Termite to an alleged attack on a U.S. family health center.

Why Healthcare Breaches Come With Added Risks

It’s worth noting that healthcare entities handle large amounts of very sensitive information. For example, a patient file often contains names, date of birth, contact information, insurance information, and treatment information. Some records may also include government identification numbers or financial information.

Unlike a password, you cannot simply change medical information after an exposure. That can make healthcare data valuable to criminals. Scammers use this kind of data for all sorts of scams, identity theft, fake insurance claims, phony medical bills, even pretty realistic phishing messages.

With enough medical details, it’s easy for a scam to seem legit. Someone could call you claiming they’re calling from a clinic or your insurance provider. They mention a few things from your records, making you believe they’re not scammers, and then proceed to make you share more personal data or even make a payment.

Ransomware attacks on healthcare systems kept going strong through the first half of 2026. Researchers have reported continued attacks across healthcare providers and related services.

A report from Comparitech in July 2026 found a 14% jump in ransomware attacks on health care, 360 cases in the last half of 2025, and 410 in the first half of 2026. The targeting of healthcare extends beyond ransomware; a hacker recently breached an Iranian health platform, exposing 700,000 patient records. This is an average of 2.3 attacks per day.

Out of these 410 attacks, 247 attacks were on hospitals and other healthcare facilities that provide direct patient services. The remaining 163 hit healthcare businesses, such as pharmaceutical and medical device manufacturers.

What’s Next for Affinia Healthcare Regarding the Allegation

Affinia Healthcare will have to figure out if the attackers stole any data or not, and from what time frame. If a breach occurs, Affinia Healthcare will also have to figure out the people it affected and assess the records.

Some additional questions are: When did the attack begin? Did the attack encrypt or disrupt any systems? Did the attackers access patient records? How many people may be affected? Were financial or identity documents involved? If it indeed happened, have they reported it to regulators?

Healthcare organizations may have legal duties to notify affected people after certain data breaches. The timing of those notices can depend on the facts of the case and the laws that apply. At this stage, there is no confirmed public answer to these questions.

What Patients Should Do

Patients shouldn’t assume, based on the claims, that the alleged incident exposed their information. The breach claim remains unverified. Still people should stay alert and cautious. Any message claiming to be from Affinia Healthcare could be a scam.

If someone asks for your personal info, passwords, account codes, insurance info, or financial details, calls, email or text, ignore such. Affina would never call you asking for any such information.

Worried your records might be compromised? Reach out to Affinia Healthcare via a phone number you trust or through their official website. They should not use contact details included in an unexpected message. Additionally, patients must also be wary of any new claims, bills, or activity in their accounts.

The breach remains unconfirmed. Everyone should, therefore, treat the incident as just a ransomware claim, not a confirmed data breach.

Share this article

About the Author

Joahn G

Joahn G

Cyber Threat Journalist

Joahn is a cyber threat journalist dedicated to tracking the evolving landscape of digital risks. His reporting focuses on ransomware gangs, data breach incidents, and state-sponsored cyber operations. By analyzing threat actor motives and tactics, he provides timely intelligence that helps readers understand and anticipate the security challenges of tomorrow.

View all posts by Joahn G >
Comments (0)

No comments.