Ransomware group incransom hits hsc.mb.ca
hsc.mb.ca — a healthcare target operating in CA has been listed by the incransom ransomware group on 2026-10-10. The information below reflects what the threat actor has publicly claimed on their leak site; the details have not been independently verified.
Incident Report
| Target Organization | hsc.mb.ca |
|---|---|
| Threat Group | incransom |
| Summary | The Health Sciences Centre in Winnipeg, one of the largest medical institutions, was targeted by us that resulted in the largest data breach among healthcare institutions. Our group chose not to completely disrupt the facility’s operations, recognizing the potentially devastating consequences that such an action could have had on patients’ lives and health. Nevertheless, Health Sciences Centre management stated that no sensitive data had been affected, despite having been informed otherwise. The data included, but was not limited to, the following information: Patient medical records: Full name, date of birth, address and phone number Hospital medical record number Diagnoses, medical history, allergies and medications Laboratory results, imaging reports Appointment dates, treatment details and physician information. Employee and healthcare professional information: Names, contact details, dates of birth and employee numbers Employment, payroll and banking information Professional credentials, work schedules and departmental assignments. Financial and insurance information: Billing records and payment histories Insurance or benefits claim information. Confidential hospital documents: Internal emails and staff communications System configurations, network diagrams and security procedures Database backups and exported spreadsheets. We would have very much preferred to avoid making this data breach public, but the management has left us with no other choice. |
| Date of Breach | 2026-10-10 |
| Discovery Date | 2026-10-11 |
| Region | CA |
| Target Domain | hsc.mb.ca |
| Business Sector | Healthcare |
| Severity | MEDIUM |
Claim by incransom
The Health Sciences Centre in Winnipeg, one of the largest medical institutions, was targeted by us that resulted in the largest data breach among healthcare institutions. Our group chose not to completely disrupt the facility’s operations, recognizing the potentially devastating consequences that such an action could have had on patients’ lives and health. Nevertheless, Health Sciences Centre management stated that no sensitive data had been affected, despite having been informed otherwise. The data included, but was not limited to, the following information: Patient medical records: Full name, date of birth, address and phone number Hospital medical record number Diagnoses, medical history, allergies and medications Laboratory results, imaging reports Appointment dates, treatment details and physician information. Employee and healthcare professional information: Names, contact details, dates of birth and employee numbers Employment, payroll and banking information Professional credentials, work schedules and departmental assignments. Financial and insurance information: Billing records and payment histories Insurance or benefits claim information. Confidential hospital documents: Internal emails and staff communications System configurations, network diagrams and security procedures Database backups and exported spreadsheets. We would have very much preferred to avoid making this data breach public, but the management has left us with no other choice.
Posted by the incransom threat actor on its public leak site. This is the group's own statement and has not been independently verified by HackerFeeds.
Sources
Victim website
hsc.mb.ca
Leak post (onion / Tor)
http://incblog6qu4y4mm4zvw5nrmue6qbwtgjsxpw6b7ixzssu36tsajldoad.onion/blog/disclosures/6acad92e9cd108bf2630db9c
Open this URL in Tor Browser. Browsing leak sites carries real risk — view passively, never click further.
Disclaimer
HackerFeeds does not engage in the exfiltration, downloading, taking, hosting, viewing, reposting, or disclosure of any stolen information. All breach data reported here is sourced from publicly available threat intelligence feeds for awareness purposes only.

