Cyber Incident Victim: Rehoboth McKinley Christian Health Care Services
Timeline
Summary
Rehoboth Mckinley Christian Health Care Services in New Mexico experienced a ransomware attack by Conti threat actors, resulting in the theft of sensitive patient and operational data. The attackers leaked samples of compromised files, including handwritten injury reports, medical care documentation, demographic details, protected health information, driver’s licenses, a Social Security card, a prescription, and a passport as proof of the breach. The healthcare provider had not publicly acknowledged the incident or confirmed the attack at the time of reporting, with no statement on its website regarding the compromise.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 2 techniques |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
On or around February 15, 2021, Rehoboth Mckinley Christian Health Care Services (RMCHCS), a healthcare provider in New Mexico, fell victim to a ransomware attack perpetrated by the Conti threat actor group. The attackers compromised RMCHCS's systems, exfiltrating sensitive data before encrypting files. Conti listed RMCHCS on its dedicated leak site on February 5, 2025, publicly claiming responsibility for the attack. As proof of the data breach, Conti published a limited sample of stolen files, which included handwritten injury reports, patient care documentation containing demographic details and protected health information (PHI), images of driver’s licenses, a Social Security card, a prescription, and a passport. These records exposed personally identifiable information (PII) and medical details of affected individuals. The attackers did not disclose the full scope of compromised data at the time of initial disclosure, though the sample suggested significant exposure of sensitive patient and administrative records.

The attack disrupted RMCHCS's operations, though the specific duration and extent of service interruptions were not detailed in available sources. Conti’s leak site posting indicated potential further data releases unless RMCHCS engaged in negotiations, though no explicit ransom demand or deadline was publicly disclosed alongside the sample. RMCHCS did not issue an immediate public statement regarding the incident, as its website contained no breach notification or service disruption alerts as of February 6, 2025. DataBreaches.net contacted RMCHCS for confirmation but received no response prior to the article’s publication. The exposed sample data posed immediate risks of identity theft, medical fraud, and privacy violations for impacted patients, particularly given the inclusion of government-issued identification and financial identifiers like Social Security numbers. No third-party forensic or law enforcement involvement was confirmed in the available reporting.
