VORANT. Threat Intelligence Sign in Get the full feed

INC Ransom extorts Partnered Health over Bupa deal

high threat healthcarefinancial-services

INC Ransom claims a 3.2TB breach of Australian healthcare provider Partnered Health, threatening to leak patient and Bupa corporate data unless Quadrant Private Equity resumes negotiations before its $450M Bupa acquisition closes.

A ransomware/extortion group operating under the INC Ransom brand claims to have exfiltrated 3.2TB of data from Partnered Health, a network of 60+ Australian primary care, occupational health, and psychology clinics owned by Quadrant Private Equity. The actor alleges access to 21 servers including nine Active Directory controllers, eleven clinical database servers, and a central SQL server, yielding over 2.3 million files spanning 27 years (1999-2026) of patient medical records, staff HR data (including passports and AHPRA registrations), payroll, financial records, and clinical governance documentation.

The extortion note is notable for explicitly leveraging Partnered Health's pending ~$450M AUD acquisition by Bupa, which is currently awaiting ACCC and FIRB regulatory approval. The actor claims to also hold Bupa corporate data — billing agreements, fund pricing tables, patient invoices, and active Bupa web portal session cookies — and is threatening a staged public release (HR records, then SQL databases, then Bupa corporate data with direct notification to regulators and Bupa leadership, then a full data dump) if a 10-day deadline for renewed negotiations is not met. The group disputes the victim's public characterization of the incident as limited in scope.

This is a high-impact healthcare data extortion case involving highly sensitive patient medical and financial records at scale, compounded by potential collateral exposure of a major insurer (Bupa) and interference risk to a pending regulated M&A transaction. No technical indicators (malware samples, infrastructure, initial access vector, or CVEs) were disclosed in this extortion notice.

Mentioned in this report

Threat actors INC Ransom
Malware INC Ransom

Source reporting: https://www.ransomware.live/id/UEFSVE5FUkVEIEhFQUxUSCBHUk9VUEBpbmNyYW5zb20=

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free