Ransomware Group rhysida Hits: General Santos Doctors Hospital
Summary
In the latest cybersecurity news, General Santos Doctors Hospital — an organization based in PH — has fallen victim to a ransomware attack conducted by the group rhysida. This data breach, discovered on 2026-09-10T18:30:09.798035+00:00, underscores the increasing need for proactive cybersecurity defenses as we continue through 2026.
Incident Report
| Attribute | Information |
|---|---|
| Target Organization | General Santos Doctors Hospital |
| Threat Group | rhysida |
| Summary | General Santos Doctors Hospital 3.502.636 files, total volume ~2.44 TBPatient data (PHI) � name-tagged scans across department shares (surgical pathology, hemodialysis charts, admission records), cancer-center dossiers with PhilHealth IDs, lab quotations incl. cancer-marker tests with birth dates, PhilHealth claims monitoring, neonatal (NICU) dataStaff and professionals � accredited physicians register (cell numbers, PRC licenses, PhilHealth IDs), named payroll workbooks (incl. the affiliated diagnostic center), HR dossiers, staff passport scans, drug-test filesMoney, audit and governance � audited financial statements personally signed by chairman/treasurer/CFO with BIR stamps, balance sheet, all bank accounts across six-plus banks, internal-audit memos on (cashier discrepancies and cash shortages), SEC stockholders’ minutes, payroll bank-upload batches, related-party entities on the same sharesLeadership personal data � personal cell numbers of the president, hospital administrator and board members More |
| Date of Breach | 2026-09-10T18:29:37.882456+00:00 |
| Discovery Date | 2026-09-10T18:30:09.798035+00:00 |
| Region | PH |
| Business Sector | Healthcare |
How to reduce your ransomware risk
Most ransomware intrusions start with a stolen password or a phishing email. A few proactive steps sharply cut your exposure:
- realistic phishing tests — close the gap attackers exploit.
- train staff to spot attacks — close the gap attackers exploit.
Want to know if you’re already exposed? Run a free scan with the HookPhish data breach checker.
Disclaimer
HookPhish does not engage in the exfiltration, downloading, taking, hosting, viewing, reposting, or disclosure of any stolen information. All breach data reported here is sourced from publicly available threat intelligence feeds for awareness purposes only.
