INC Ransom extorts Partnered Health over Bupa deal
INC Ransom claims a 3.2TB breach of Australian healthcare provider Partnered Health, threatening to leak patient and Bupa corporate data unless Quadrant Private Equity resumes negotiations before its $450M Bupa acquisition closes.
A ransomware/extortion group operating under the INC Ransom brand claims to have exfiltrated 3.2TB of data from Partnered Health, a network of 60+ Australian primary care, occupational health, and psychology clinics owned by Quadrant Private Equity. The actor alleges access to 21 servers including nine Active Directory controllers, eleven clinical database servers, and a central SQL server, yielding over 2.3 million files spanning 27 years (1999-2026) of patient medical records, staff HR data (including passports and AHPRA registrations), payroll, financial records, and clinical governance documentation.
The extortion note is notable for explicitly leveraging Partnered Health's pending ~$450M AUD acquisition by Bupa, which is currently awaiting ACCC and FIRB regulatory approval. The actor claims to also hold Bupa corporate data — billing agreements, fund pricing tables, patient invoices, and active Bupa web portal session cookies — and is threatening a staged public release (HR records, then SQL databases, then Bupa corporate data with direct notification to regulators and Bupa leadership, then a full data dump) if a 10-day deadline for renewed negotiations is not met. The group disputes the victim's public characterization of the incident as limited in scope.
This is a high-impact healthcare data extortion case involving highly sensitive patient medical and financial records at scale, compounded by potential collateral exposure of a major insurer (Bupa) and interference risk to a pending regulated M&A transaction. No technical indicators (malware samples, infrastructure, initial access vector, or CVEs) were disclosed in this extortion notice.
Mentioned in this report
Source reporting: https://www.ransomware.live/id/UEFSVE5FUkVEIEhFQUxUSCBHUk9VUEBpbmNyYW5zb20=
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free