Healthcare provider · Primary and specialty care services · Medical practice network · USA
Primary and specialty care medical group.
The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.
Kansas-based Sunflower Medical Group detected unusual network activity on January 7, 2025 and determined an unauthorized party had accessed its systems around December 15, 2024, copying files with sensitive personal information. The Rhysida ransomware group claimed responsibility, advertising an exfiltrated ~3 TB SQL database (claimed to hold data on roughly 400,000 patients). Sunflower filed a breach notice with the Maine Attorney General on March 7, 2025 and notified affected individuals. Official filings put the affected count at 220,968; a DataBreach.com parse recorded 356,822. Exposed data included names, addresses, dates of birth, Social Security numbers, driver's license numbers, medical information, and health insurance information. The company later agreed to a class-action settlement of up to $1.2 million.
Full threat analysis, exploitation vectors, and principal guidance below.
11 additional sections · verified field analysis · defensive doctrine
221K records analyzed
Sunflower Medical Group is a Kansas-based primary and specialty care medical practice providing outpatient healthcare across multiple clinics. It maintains patient identity, contact, insurance, billing, scheduling, and treatment records spanning primary and specialty care relationships.
Medical practice networks collect patient identity, contact, insurance, billing, appointment, and treatment records across primary and specialty care operations.
After the December 2024 intrusion (detected January 7, 2025), Sunflower notified affected individuals, filed with state regulators, and offered identity-theft protection. It later agreed to a class-action settlement of up to $1.2 million. The Rhysida ransomware group claimed the attack and advertised a 3 TB SQL database for sale.
The exposure combined identity, government-ID, and clinical data (Social Security numbers, driver's licenses, medical information, health insurance) for more than 220,000 patients, creating severe identity-theft, medical-fraud, and insurance-abuse risk. Rhysida's exfiltration of a multi-terabyte database and its offer for sale heighten the likelihood of downstream misuse, and the breach generated significant class-action liability.
• Medical identity fraud and insurance abuse using medical and insurance data | • Identity theft and synthetic identity construction using SSN, DOB, and driver's license | • Identity verification bypass using name + DOB + government ID | • Targeted phishing and vishing referencing medical care | • Doxxing and physical targeting from exposed home addresses
A healthcare-linked breach: exposure ties a named individual to a provider relationship and, where clinical or insurance data is present, to conditions and treatment. For a high-profile principal this is targeting-grade, not merely identity-theft-grade: the combination lets an adversary locate, impersonate, or pressure the principal with little additional work.
Motivation: Financial extortion
A ransomware-as-a-service group using double extortion. CISA reporting notes targeting across education, manufacturing, IT, government, and healthcare.
Enter your email to check whether your data appears in this breach. We’ll send a 6-digit code to confirm it’s your address.
Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.
Request Consultation