Healthcare provider · Behavioral health and support services · Community care provider · USA
Community mental health and developmental disability services provider.
The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.
Spindletop Center, a Beaumont, Texas community mental-health and intellectual/developmental-disability provider (the local mental-health authority for its region), suffered a cyberattack around September 23-29, 2025 that rendered systems temporarily inoperable. The Rhysida ransomware group claimed responsibility on October 30, 2025, demanding ~15 BTC (~$1.65M). Spindletop reported 88,863 individuals affected to HHS. Exposed data included names, Social Security numbers, driver's license/government ID numbers, diagnosis information, and case numbers. (NOTE: prior record listed 217,644 affected and omitted medical/diagnosis; corrected to 88,863 with diagnosis and driver's license added.) 42 CFR Part 2 may apply where substance-use records are involved.
Full threat analysis, exploitation vectors, and principal guidance below.
11 additional sections · verified field analysis · defensive doctrine
89K records analyzed
Spindletop Center is a community mental-health and intellectual/developmental-disability (IDD) services provider based in Beaumont, Texas, serving as the local mental-health authority for Jefferson, Hardin, and Orange counties. It provides mental-health treatment, IDD services, substance-use programs, and crisis/community support, maintaining highly sensitive clinical, case-management, and identity records.
Behavioral health and support-service providers collect highly sensitive patient identity, treatment, counseling, insurance, and social-service records tied to mental health and community care.
Spindletop Center was hit by a cyberattack around September 23-29, 2025 that rendered systems temporarily inoperable. The Rhysida ransomware group claimed responsibility on October 30, 2025, demanding roughly 15 bitcoin (~$1.65M) and threatening to publish. Spindletop reported 88,863 individuals affected to HHS, and its investigation concluded on December 3, 2025; class-action investigations followed.
Because appearing in Spindletop's records signals a mental-health, developmental-disability, or substance-use service relationship, exposure carries acute stigma, discrimination, and coercion risk on top of identity-theft harm from Social Security numbers and driver's licenses. Diagnosis information and case numbers deepen the privacy harm for a vulnerable population, and disclosure of disability status itself creates discrimination risk.
• Stigma-based targeting and coercion tied to mental-health, developmental-disability, or substance-use service status | • Identity theft and synthetic identity construction using SSN and driver's license | • Medical identity fraud and insurance abuse using diagnosis data | • Discrimination risk from disclosure of disability/behavioral-health status | • Targeted phishing and vishing; doxxing from exposed home addresses
A healthcare-linked breach: exposure ties a named individual to a provider relationship and, where clinical or insurance data is present, to conditions and treatment. For a high-profile principal this is targeting-grade, not merely identity-theft-grade: the combination lets an adversary locate, impersonate, or pressure the principal with little additional work.
Motivation: Financial extortion
A ransomware-as-a-service group using double extortion. CISA reporting notes targeting across education, manufacturing, IT, government, and healthcare.
Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.
Request Consultation