CSIDB logo
Incident

Rehoboth McKinley Christian Health Care Services

Incident posture

Attack window
Feb 2021
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2026-03-09 20:26

Linked entities

Victim
Rehoboth McKinley Christian Health Care Services
Threat actors
1 actor
Sources
2 sources

Timeline

Occurred
Feb 2021
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Rehoboth Mckinley Christian Health Care Services in New Mexico experienced a ransomware attack by Conti threat actors, resulting in the theft of sensitive patient and operational data. The attackers leaked samples of compromised files, including handwritten injury reports, medical care documentation, demographic details, protected health information, driver’s licenses, a Social Security card, a prescription, and a passport as proof of the breach. The healthcare provider had not publicly acknowledged the incident or confirmed the attack at the time of reporting, with no statement on its website regarding the compromise.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

2 techniques

Description

On or around February 15, 2021, Rehoboth Mckinley Christian Health Care Services (RMCHCS), a healthcare provider in New Mexico, fell victim to a ransomware attack perpetrated by the Conti threat actor group. The attackers compromised RMCHCS's systems, exfiltrating sensitive data before encrypting files. Conti listed RMCHCS on its dedicated leak site on February 5, 2025, publicly claiming responsibility for the attack. As proof of the data breach, Conti published a limited sample of stolen files, which included handwritten injury reports, patient care documentation containing demographic details and protected health information (PHI), images of driver’s licenses, a Social Security card, a prescription, and a passport. These records exposed personally identifiable information (PII) and medical details of affected individuals. The attackers did not disclose the full scope of compromised data at the time of initial disclosure, though the sample suggested significant exposure of sensitive patient and administrative records.

The attack disrupted RMCHCS's operations, though the specific duration and extent of service interruptions were not detailed in available sources. Conti’s leak site posting indicated potential further data releases unless RMCHCS engaged in negotiations, though no explicit ransom demand or deadline was publicly disclosed alongside the sample. RMCHCS did not issue an immediate public statement regarding the incident, as its website contained no breach notification or service disruption alerts as of February 6, 2025. DataBreaches.net contacted RMCHCS for confirmation but received no response prior to the article’s publication. The exposed sample data posed immediate risks of identity theft, medical fraud, and privacy violations for impacted patients, particularly given the inclusion of government-issued identification and financial identifiers like Social Security numbers. No third-party forensic or law enforcement involvement was confirmed in the available reporting.

Sources

Sources available to members: 2 sources.

CSIDB