University · Medical education and research · Academic health institution · USA
Academic health sciences institution.
The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.
Between September 17-29, 2024, TTUHSC suffered a ransomware attack (claimed by the Interlock group, which alleged theft of 2.6TB / ~2.1M files). Notifications began January 2025; reports put the affected population at roughly 1.2-1.46 million patients. Exposed data included names, addresses, dates of birth, Social Security numbers, drivers-license/government IDs, financial account information, health-insurance details, diagnosis/treatment information, medical record numbers, and billing/claims data.
Full threat analysis, exploitation vectors, and principal guidance below.
10 additional sections · verified field analysis · defensive doctrine
1.2M records analyzed
Texas Tech University Health Sciences Center (TTUHSC) is an academic medical center and health-sciences university system in Texas.
Academic medical centers collect student, staff, patient, and administrative records, often including names, phone numbers, addresses, and other health-system contact data across clinical and educational operations.
This is a severe PHI breach: SSNs, government IDs, financial accounts, and detailed medical data together enable identity theft, financial fraud, and medical fraud.
• SIM swap attacks where phone numbers are present
An education-sector breach: student, staff and identity records support identity theft and targeted phishing. For a high-profile principal this is targeting-grade, not merely identity-theft-grade: the combination lets an adversary locate, impersonate, or pressure the principal with little additional work.
Motivation: Financial extortion
A ransomware and data-extortion operation active since around September 2024, impacting businesses and critical infrastructure across North America and Europe via a double-extortion model (encrypt plus steal).
Enter your email to check whether your data appears in this breach. We’ll send a 6-digit code to confirm it’s your address.
Be the first to know when new breaches are disclosed. Free forever — confirm your email with a 6-digit code.
Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.
Request Consultation