Healthcare Provider · Post-operative care and recovery services · Post-surgical care provider · USA
Provider of durable medical equipment, orthotics, and post-operative supplies.
The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.
Team Post Op, LLC (operator of teampostop.net), a Florida DME and orthotics provider, was identified as a ransomware victim on or around July 24-25, 2025, when the INC Ransom (INC_RANSOM) group listed it on its dark-web leak site. A DataBreach.com parse recorded roughly 150,185 records including names, home addresses, phone numbers, emails, and Social Security numbers. Because Team Post Op serves 16,000+ patients per year, the figure likely reflects cumulative records. The company did not publicly confirm the incident or itemize exposed data; reporting notes patient PHI (dates of birth, insurance, medical-device usage, order histories) may also have been involved but was not independently confirmed in circulation.
Full threat analysis, exploitation vectors, and principal guidance below.
11 additional sections · verified field analysis · defensive doctrine
150K records analyzed
Team Post Op, LLC is a Florida-based provider of durable medical equipment (DME), orthotics, and post-operative supplies, serving more than 16,000 adult and pediatric patients annually through the website teampostop.net. It maintains patient identity, contact, insurance, prescribing/order, and delivery records tied to post-surgical recovery and home medical equipment.
Post-surgical care providers collect patient identity, contact, billing, scheduling, and treatment or recovery records tied to surgical aftercare and follow-up services.
Team Post Op was identified as a ransomware victim around July 24-25, 2025 when the INC Ransom (INC_RANSOM) group listed it on its dark-web leak site. The company did not issue a formal public statement, and details relied on threat-actor claims and third-party monitoring; class-action investigations have since been opened.
Because Team Post Op supplies post-operative and home medical equipment, appearing in its records can reveal recent surgery, recovery status, and medical-device needs, adding sensitivity to standard identity-theft risk from exposed Social Security numbers and contact data. Its adult and pediatric patient base raises the stakes, and the lack of a formal disclosure left patients dependent on third-party reporting to learn of exposure.
• Identity theft and synthetic identity construction using SSN | • Targeted phishing and vishing referencing surgery, recovery, or medical-equipment orders | • Doxxing and physical targeting from exposed home addresses | • SIM swap attacks where phone numbers are present | • Potential medical-fraud and insurance abuse if reported PHI is in the dump
A healthcare-linked breach: exposure ties a named individual to a provider relationship and, where clinical or insurance data is present, to conditions and treatment. For a high-profile principal this is targeting-grade, not merely identity-theft-grade: the combination lets an adversary locate, impersonate, or pressure the principal with little additional work.
Motivation: Financial extortion
A ransomware and data extortion group active since at least July 2023. MITRE describes it as targeting industrial, healthcare, and education sectors in the United States and Europe.
Enter your email to check whether your data appears in this breach. We’ll send a 6-digit code to confirm it’s your address.
Be the first to know when new breaches are disclosed. Free forever — confirm your email with a 6-digit code.
Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.
Request Consultation