Cyberattack at French hospital exposes health data of 750,000 patients

Teilen:

A data breach at an unnamed French hospital exposed the medical records of 750,000 patients after a threat actor gained access to its electronic patient record system.

A threat actor using the nickname ‘nears’ (previously near2tlg) claimed to have attacked multiple healthcare facilities in France, alleging that they have access to the patient records of over 1,500,000 people.

The hacker claims they breached MediBoard by Software Medical Group, a company offering Electronic Patient Record (EPR) solutions across Europe.

Softway Medical Group has confirmed that hackers have compromised a MediBoard account. However, it noted that this was not the result of a software vulnerability or misconfiguration on their part, but rather through the use of stolen credentials used by the hospital.

In a letter sent to French media and shared with BleepingComputer by LeMagIT’s editor-in-chief, Valéry Rieß-Marchive, Softway Medical Group says the exposed data was not directly managed by them, but rather hosted by the hospital.

“On November 19, 2024, a cyberattack was detected within a healthcare facility using the Mediboard software,” reads the machine-translated email.

“We want to emphasize that the affected health data were not hosted by Softway Medical Group.”

Letter

BleepingComputer contacted Softway Medical Group for clarifications on which account and at what level was compromised, and a spokesperson shared the following statement:

“We can confirm that our software is not responsible, but rather, a privileged account within the client’s infrastructure was compromised by an individual who exploited the standard functions of the solution,” the Softway Medical Group told BleepingComputer.

“This hypothesis has been substantiated. It is therefore neither due to improper implementation of the software nor human error.”

Selling access to hospitals

This all unfolded after the threat actor began selling what they claimed was access to the MediBoard platform for multiple French hospitals, including Centre Luxembourg, Clinique Alleray-Labrouste, Clinique Jean d’Arc, Clinique Saint-Isabelle, and Hôpital Privé de Thiais.

This access allegedly would let the buyer view the hospitals’ sensitive healthcare and billing information, patient records, and the ability to schedule and modify appointments or medical records.

1
Quelle: BleepingComputer

To prove that they gained access to the MediBoard accounts, the hacker also put the records of 758,912 patients from an unnamed French hospital up for sale.

2
Quelle: BleepingComputer

These records allegedly contain the following information:

  • Vollständiger Name
  • Datum der Geburt
  • Gender
  • Home address
  • Phone number
  • E-Mail Adresse
  • Physician
  • Prescriptions
  • Health card history

The data was offered for purchase to three users, and currently, no buyers have been declared on the sale listing.

Even if the data isn’t sold, there’s always a risk of being leaked online for free, making it available to the broader cybercrime community.

The type of data exposed in this incident raises the risk of phishing, scamming, and social engineering for impacted people.

Update 11/21: BleepingComputer has learned that all of the affected hospitals belong to a single entity, Aléo Santé, which explains how the threat actor got access to all of them by compromising one privileged MediBoard account not in Softway’s direct control.

Bill Toulas

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
2:42 am, Juli 5, 2025
Wetter-Symbol 19°C
L: 17° | H: 19°
overcast clouds
Luftfeuchtigkeit: 57 %
Druck: 1019 mb
Wind: 15 mph WSW
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 90%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:50 am
Sonnenuntergang: 9:19 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
17° | 19°°C 0.65 mm 65% 12 mph 82 % 1019 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
15° | 21°°C 1 mm 100% 11 mph 90 % 1011 mb 0 mm/h
Mo. Juli 07 10:00 pm
Wetter-Symbol
14° | 22°°C 0.22 mm 22% 13 mph 78 % 1015 mb 0 mm/h
Di. Juli 08 10:00 pm
Wetter-Symbol
14° | 26°°C 0 mm 0% 11 mph 72 % 1019 mb 0 mm/h
Mi. Juli 09 10:00 pm
Wetter-Symbol
18° | 30°°C 0 mm 0% 9 mph 79 % 1022 mb 0 mm/h
Today 4:00 am
Wetter-Symbol
16° | 19°°C 0 mm 0% 10 mph 57 % 1019 mb 0 mm/h
Today 7:00 am
Wetter-Symbol
16° | 18°°C 0.65 mm 65% 10 mph 64 % 1019 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
19° | 19°°C 0 mm 0% 11 mph 70 % 1018 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
18° | 18°°C 0 mm 0% 10 mph 76 % 1015 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
19° | 19°°C 0 mm 0% 12 mph 82 % 1014 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
19° | 19°°C 0 mm 0% 11 mph 82 % 1012 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
18° | 18°°C 0.2 mm 20% 10 mph 81 % 1012 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
16° | 16°°C 0 mm 0% 9 mph 81 % 1011 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€91,680.95
-1.44%
Ethereum(ETH)
€2,134.31
-2.98%
Fesseln(USDT)
€0.85
0.00%
XRP(XRP)
€1.88
-2.06%
Solana(SOL)
€125.68
-3.14%
USDC(USDC)
€0.85
0.00%
Dogecoin(DOGE)
€0.138508
-5.36%
Shiba Inu(SHIB)
€0.000009
-4.13%
Pepe(PEPE)
€0.000008
-5.32%
Nach oben scrollen