Ransomware Group incransom Hits: PARTNERED HEALTH GROUP
Summary
In the latest cybersecurity news, PARTNERED HEALTH GROUP — an organization based in AU — has fallen victim to a ransomware attack conducted by the group incransom. This data breach, discovered on 2026-07-30T16:30:13.670561+00:00, underscores the increasing need for proactive cybersecurity defenses as we continue through 2026.
Incident Report
| Attribute | Information |
|---|---|
| Target Organization | PARTNERED HEALTH GROUP |
| Threat Group | incransom |
| Summary | PARTNERED HEALTH GROUP — Australia ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ Industry: Healthcare — Primary Care, Occupational Health, PENDING ACQUISITION: Bupa — ~$450,000,000 AUD ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ Date of access: 23 June 2026 ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ ▪ Complete patient medical records from 21 GP clinics — ▪ Full SQL database dumps — ZedMed (patient management), ▪ 11 complete Best Practice patient database backups — ▪ Staff HR files — employment contracts, passport scans, ▪ Bupa corporate data — direct billing agreements, ▪ Financial records — QuickBooks databases (2004-2026), ▪ Clinical governance — full RACGP accreditation files, ▪ 27 years of accumulated medical data (1999-2026) across ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ Partnered Health was given the opportunity to resolve this Their public statement of July 15 describes the breach as The reality: 3.2 terabytes. 2.3 million files. 21 servers. And critically — the data includes Bupa’s own corporate We understand this acquisition matters. $450 million is This is not a threat. This is a deadline. ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ Partnered Health has 10 days to resume negotiations If no agreement is reached: Stage 1 — Complete file tree listing (2.3M files) Stage 2 — SQL databases (ZedMed, Payroll, ECG) Stage 3 — Bupa corporate data, fund tables, Stage 4 — Full 3.2 TB data dump made available |
| Date of Breach | 2026-07-30T01:00:00+00:00 |
| Discovery Date | 2026-07-30T16:30:13.670561+00:00 |
| Region | AU |
| Business Sector | Healthcare |
How to reduce your ransomware risk
Most ransomware intrusions start with a stolen password or a phishing email. A few proactive steps sharply cut your exposure:
- real-time breach alerts — close the gap attackers exploit.
- phishing simulations — close the gap attackers exploit.
Want to know if you’re already exposed? Run a free scan with the HookPhish data breach checker.
Disclaimer
HookPhish does not engage in the exfiltration, downloading, taking, hosting, viewing, reposting, or disclosure of any stolen information. All breach data reported here is sourced from publicly available threat intelligence feeds for awareness purposes only.
