Texas Tech University Health Sciences Center 2024 Data Breach

Texas Tech University Health Sciences Center Breach (2024): 1.2 Million Patient & Student Records Exposed

University · Medical education and research · Academic health institution · USA

Texas Tech University Health Sciences Center Breach (2024): 1.2 Million Patient & Student Records Exposed

Academic health sciences institution.

Confirmed · ObscureIQ Intelligence
Breach Risk Index i
69/100
Lower riskHigher risk
High and current: recent, valuable data circulating on the dark web now.
Data Sensitivity i
Elevated
Exposed data raises the risk of fraud, targeting, and impersonation. Proactive steps are warranted.
1.2MRecords
2024Year

The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.

Classification Tags
InterlockRansomware / ExtortionEducationPatient; Student2024

Breach Summary

Between September 17-29, 2024, TTUHSC suffered a ransomware attack (claimed by the Interlock group, which alleged theft of 2.6TB / ~2.1M files). Notifications began January 2025; reports put the affected population at roughly 1.2-1.46 million patients. Exposed data included names, addresses, dates of birth, Social Security numbers, drivers-license/government IDs, financial account information, health-insurance details, diagnosis/treatment information, medical record numbers, and billing/claims data.

Full threat analysis, exploitation vectors, and principal guidance below.

10 additional sections · verified field analysis · defensive doctrine

Querying breach corpus…
Cross-referencing exposed field types…
Resolving threat-actor attribution…
Compiling principal risk advisory…

1.2M records analyzed

About Texas Tech University Health Sciences Center

Texas Tech University Health Sciences Center (TTUHSC) is an academic medical center and health-sciences university system in Texas.

Why They Hold Your Data

Academic medical centers collect student, staff, patient, and administrative records, often including names, phone numbers, addresses, and other health-system contact data across clinical and educational operations.

Data Points Exposed

2 verified field types
Full Name
Phone Number

Breach Impact

This is a severe PHI breach: SSNs, government IDs, financial accounts, and detailed medical data together enable identity theft, financial fraud, and medical fraud.

Exploitation & Downstream Threats

• SIM swap attacks where phone numbers are present

Principal Risk Advisory

What this means for a principal

An education-sector breach: student, staff and identity records support identity theft and targeted phishing. For a high-profile principal this is targeting-grade, not merely identity-theft-grade: the combination lets an adversary locate, impersonate, or pressure the principal with little additional work.

What You Should Do

  1. Freeze credit at all three bureaus and monitor for new-account and tax-refund fraud.
  2. Treat the home address as exposed: review mail and package handling and physical-security routines, and brief household staff to verify unusual requests.
  3. Watch for medical-benefit fraud and health-themed phishing that references real provider relationships.
  4. Do not use unofficial 'am I affected' lookups; several are themselves harvesting operations.

How ObscureIQ Can Help

  1. Corpus confirmation: determine whether and where the principal (plus household and staff) appear in this dataset and which specific fields are exposed for them.
  2. Exposure mapping and footprint neutralization: cross-reference against broker-available data and suppress still-removable elements, prioritizing address and phone, since this record re-seeds broker networks.
  3. ThreatWatch tuned to this incident's identifiers and misuse pattern (impersonation and targeting patterns, not generic credential monitoring).
I
Threat Actor: InterlockConfidence: High
Ransomware group

Motivation: Financial extortion
A ransomware and data-extortion operation active since around September 2024, impacting businesses and critical infrastructure across North America and Europe via a double-extortion model (encrypt plus steal).

Read the full threat-actor profile →

Protect Yourself

Check If You're Affected

Enter your email to check whether your data appears in this breach. We’ll send a 6-digit code to confirm it’s your address.

Get Free Breach Alerts

Be the first to know when new breaches are disclosed. Free forever — confirm your email with a 6-digit code.

High-Risk? Get an Exposure Audit

Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.

Request Consultation