teampostop.net 2025 Data Breach

Team PostOp Post-Surgical Care Provider Breach (2025): 150K Patient SSN & Home Address Records Exposed

Healthcare Provider · Post-operative care and recovery services · Post-surgical care provider · USA

Team PostOp Post-Surgical Care Provider Breach (2025): 150K Patient SSN & Home Address Records Exposed

Provider of durable medical equipment, orthotics, and post-operative supplies.

Confirmed · ObscureIQ Intelligence
Breach Risk Index i
69/100
Lower riskHigher risk
High and current: recent, valuable data circulating on the dark web now.
Data Sensitivity i
Elevated
Exposed data raises the risk of fraud, targeting, and impersonation. Proactive steps are warranted.
150KRecords
2025Year

The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.

Crucial data exposed
SSNSocial Security Number
AddressPhysical address
Classification Tags
INC RansomRansomware / ExtortionHealthcareMedicalPatients2025

Breach Summary

Team Post Op, LLC (operator of teampostop.net), a Florida DME and orthotics provider, was identified as a ransomware victim on or around July 24-25, 2025, when the INC Ransom (INC_RANSOM) group listed it on its dark-web leak site. A DataBreach.com parse recorded roughly 150,185 records including names, home addresses, phone numbers, emails, and Social Security numbers. Because Team Post Op serves 16,000+ patients per year, the figure likely reflects cumulative records. The company did not publicly confirm the incident or itemize exposed data; reporting notes patient PHI (dates of birth, insurance, medical-device usage, order histories) may also have been involved but was not independently confirmed in circulation.

Full threat analysis, exploitation vectors, and principal guidance below.

11 additional sections · verified field analysis · defensive doctrine

Querying breach corpus…
Cross-referencing exposed field types…
Resolving threat-actor attribution…
Compiling principal risk advisory…

150K records analyzed

About teampostop.net

Team Post Op, LLC is a Florida-based provider of durable medical equipment (DME), orthotics, and post-operative supplies, serving more than 16,000 adult and pediatric patients annually through the website teampostop.net. It maintains patient identity, contact, insurance, prescribing/order, and delivery records tied to post-surgical recovery and home medical equipment.

Why They Hold Your Data

Post-surgical care providers collect patient identity, contact, billing, scheduling, and treatment or recovery records tied to surgical aftercare and follow-up services.

Recent Developments

Team Post Op was identified as a ransomware victim around July 24-25, 2025 when the INC Ransom (INC_RANSOM) group listed it on its dark-web leak site. The company did not issue a formal public statement, and details relied on threat-actor claims and third-party monitoring; class-action investigations have since been opened.

Data Points Exposed

5 verified field types
Email Address
Full Name
Phone Number
Physical address High
Social Security Number Critical

Breach Impact

Because Team Post Op supplies post-operative and home medical equipment, appearing in its records can reveal recent surgery, recovery status, and medical-device needs, adding sensitivity to standard identity-theft risk from exposed Social Security numbers and contact data. Its adult and pediatric patient base raises the stakes, and the lack of a formal disclosure left patients dependent on third-party reporting to learn of exposure.

Exploitation & Downstream Threats

• Identity theft and synthetic identity construction using SSN | • Targeted phishing and vishing referencing surgery, recovery, or medical-equipment orders | • Doxxing and physical targeting from exposed home addresses | • SIM swap attacks where phone numbers are present | • Potential medical-fraud and insurance abuse if reported PHI is in the dump

Principal Risk Advisory

What this means for a principal

A healthcare-linked breach: exposure ties a named individual to a provider relationship and, where clinical or insurance data is present, to conditions and treatment. For a high-profile principal this is targeting-grade, not merely identity-theft-grade: the combination lets an adversary locate, impersonate, or pressure the principal with little additional work.

What You Should Do

  1. Freeze credit at all three bureaus and monitor for new-account and tax-refund fraud.
  2. Treat the home address as exposed: review mail and package handling and physical-security routines, and brief household staff to verify unusual requests.
  3. Guard against SIM-swap and vishing: add a carrier port-out PIN and verify any 'support' calls independently.
  4. Do not use unofficial 'am I affected' lookups; several are themselves harvesting operations.

How ObscureIQ Can Help

  1. Corpus confirmation: determine whether and where the principal (plus household and staff) appear in this dataset and which specific fields are exposed for them.
  2. Exposure mapping and footprint neutralization: cross-reference against broker-available data and suppress still-removable elements, prioritizing address and phone, since this record re-seeds broker networks.
  3. ThreatWatch tuned to this incident's identifiers and misuse pattern (impersonation and targeting patterns, not generic credential monitoring).
IR
Threat Actor: INC RansomConfidence: High
Ransomware group

Motivation: Financial extortion
A ransomware and data extortion group active since at least July 2023. MITRE describes it as targeting industrial, healthcare, and education sectors in the United States and Europe.

Read the full threat-actor profile →

Protect Yourself

Check If You're Affected

Enter your email to check whether your data appears in this breach. We’ll send a 6-digit code to confirm it’s your address.

Get Free Breach Alerts

Be the first to know when new breaches are disclosed. Free forever — confirm your email with a 6-digit code.

High-Risk? Get an Exposure Audit

Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.

Request Consultation