HackerFeeds
All ransomware incidents
G

Ransomware group rhysida hits General Santos Doctors Hospital

HIGH
·Healthcare·PH·2026-09-10

General Santos Doctors Hospital — a healthcare target operating in PH has been listed by the rhysida ransomware group on 2026-09-10. The information below reflects what the threat actor has publicly claimed on their leak site; the details have not been independently verified.

Incident Report

Target OrganizationGeneral Santos Doctors Hospital
Threat Group
rhysida
SummaryGeneral Santos Doctors Hospital 3.502.636 files, total volume ~2.44 TBPatient data (PHI) � name-tagged scans across department shares (surgical pathology, hemodialysis charts, admission records), cancer-center dossiers with PhilHealth IDs, lab quotations incl. cancer-marker tests with birth dates, PhilHealth claims monitoring, neonatal (NICU) dataStaff and professionals � accredited physicians register (cell numbers, PRC licenses, PhilHealth IDs), named payroll workbooks (incl. the affiliated diagnostic center), HR dossiers, staff passport scans, drug-test filesMoney, audit and governance � audited financial statements personally signed by chairman/treasurer/CFO with BIR stamps, balance sheet, all bank accounts across six-plus banks, internal-audit memos on (cashier discrepancies and cash shortages), SEC stockholders' minutes, payroll bank-upload batches, related-party entities on the same sharesLeadership personal data � personal cell numbers of the president, hospital administrator and board members More
Date of Breach2026-09-10
Discovery Date2026-09-10
RegionPH
Target Domain
Business SectorHealthcare
Severity
HIGH

Claim by rhysida

General Santos Doctors Hospital 3.502.636 files, total volume ~2.44 TBPatient data (PHI) � name-tagged scans across department shares (surgical pathology, hemodialysis charts, admission records), cancer-center dossiers with PhilHealth IDs, lab quotations incl. cancer-marker tests with birth dates, PhilHealth claims monitoring, neonatal (NICU) dataStaff and professionals � accredited physicians register (cell numbers, PRC licenses, PhilHealth IDs), named payroll workbooks (incl. the affiliated diagnostic center), HR dossiers, staff passport scans, drug-test filesMoney, audit and governance � audited financial statements personally signed by chairman/treasurer/CFO with BIR stamps, balance sheet, all bank accounts across six-plus banks, internal-audit memos on (cashier discrepancies and cash shortages), SEC stockholders' minutes, payroll bank-upload batches, related-party entities on the same sharesLeadership personal data � personal cell numbers of the president, hospital administrator and board members More

Posted by the rhysida threat actor on its public leak site. This is the group's own statement and has not been independently verified by HackerFeeds.

Sources

Leak post (onion / Tor)

tor

http://rhysidafohrhyy2aszi7bm32tnjat5xri65fopcxkdfxhi4tidsg7cad.onion/archive.php?company=271

Open this URL in Tor Browser. Browsing leak sites carries real risk — view passively, never click further.

Disclaimer

HackerFeeds does not engage in the exfiltration, downloading, taking, hosting, viewing, reposting, or disclosure of any stolen information. All breach data reported here is sourced from publicly available threat intelligence feeds for awareness purposes only.