General Santos Doctors Hospital (GSDH), a prominent tertiary healthcare institution in Mindanao, Philippines, has issued a public cybersecurity advisory confirming a catastrophic data breach and extortion attack. The operation, orchestrated by the notorious Rhysida ransomware group, resulted in the exfiltration of approximately 2.44 Terabytes of highly confidential patient data—comprising more than 3.5 million files—including electronic medical records (EMR), patient lab diagnostics, surgical histories, and hospital financial ledgers.

The Incident Chronology: From Dark Web Leak to Public Disclosure

The extortion campaign escalated rapidly following initial quiet exfiltration:

  • Initial Infiltration & Silent Exfiltration: Threat actors gained initial access through an internet-facing legacy SSL-VPN portal. Over several days, the adversaries harvested administrative credentials, escalated privileges to Domain Admin, and staged bulk transfers of internal Picture Archiving and Communication System (PACS) and EMR databases.
  • Dark Web Extortion Listing (September 10, 2026): Rhysida published sample files on its dark web leak portal, boasting of stealing 2,442,112 MB of data across 3,502,636 files. The syndicate set a countdown timer demanding an 8-Bitcoin ransom (approximately ₱39 million / $680,000 USD) under threat of public auction.
  • Incident Containment & Advisory (September 25, 2026): Following two weeks of forensic investigation, system isolation, and coordination with the Philippine National Privacy Commission (NPC) and cyber defense agencies, GSDH issued its official public advisory confirming unauthorized network access and data compromise.

Anatomy of the 2.4 Terabyte Clinical Data Exfiltration

Rhysida's proof-of-concept leak packages contained extensive clinical and operational documentation:

# Directory Structure of Stolen Hospital Files (Exfiltrated Archive)
/GSDH_DATA_EXFIL/
  |-- EMR_Database_Dumps/
  |     +-- Patient_Master_Index.sql (Names, DOB, PhilHealth IDs, Addresses)
  |     +-- Clinical_Notes_2024_2026.bak (Diagnoses, Inpatient Chart Notes)
  |-- PACS_Radiology/
  |     +-- CT_Scans_DICOM/ (High-Resolution Medical Imaging)
  |     +-- MRI_Reports_PDF/ (Diagnostic Findings)
  |-- Hospital_Administration/
  |     +-- Payroll_Ledgers_2026.xlsx (Employee Salaries, Banking Numbers)
  |     +-- Physician_Licenses_Contracts.pdf (Doctor Credentials & Agreements)

Threat Actor Profile: The Rhysida Ransomware Syndicate

Rhysida operates as an aggressive Ransomware-as-a-Service (RaaS) entity known for striking vital human services—specifically healthcare facilities, schools, and government infrastructure. The group utilizes PowerShell scripts, living-off-the-land binaries (LOLBins), and PsExec to propagate across Windows domains:

MITRE ATT&CK Tactic Observed Technique Incident Execution Details
Initial Access (T1133) External Remote Services Compromised credentials on edge SSL-VPN gateway lacking MFA
Discovery (T1087) Account Discovery Execution of net user and nltest commands via PowerShell
Lateral Movement (T1021.002) SMB / Windows Admin Shares PsExec used to push ransomware binaries to clinical workstations
Exfiltration (T1567.002) Exfiltration Over Web Service Mega.nz and MegaSync client used to siphon 2.44TB of data to cloud

Defensive Remediation Checklist for Hospital Networks

  1. Decommission Legacy SSL-VPN Gateways: Eliminate legacy VPN concentrators running end-of-life firmware. Mandate phishing-resistant multi-factor authentication (FIDO2 / WebAuthn) for all remote physician and administrative access without exception.
  2. Isolate Clinical PACS and EMR Networks: Segment medical imaging (PACS/DICOM) and electronic medical record servers on dedicated VLANs isolated from general hospital office and public Wi-Fi networks. Restrict traffic between enclaves using stateful firewall inspection.
  3. Deploy Immutable Offline Backups: Maintain offline, air-gapped, or immutable cloud backups (such as AWS S3 Object Lock in compliance mode) for all vital clinical databases, ensuring rapid recovery without negotiating with extortionists.
  4. Mandatory NPC Regulatory Compliance: Covered healthcare fiduciaries under the Philippine Data Privacy Act of 2012 must report any unauthorized breach involving sensitive personal information to the National Privacy Commission within 72 hours of verification.