Data Breaches

113,000 Impacted by Data Breach at Virginia Mental Health Authority

Threat actors stole names, Social Security numbers, and financial and health information, and deployed ransomware on RBHA’s systems.

Data breach

Virginia mental health services provider Richmond Behavioral Health Authority (RBHA) says the personal information of more than 113,000 people was stolen in a recent ransomware attack.

Serving the city of Richmond, RBHA is a public agency that provides mental health support, crisis care, intellectual disability, substance abuse, and prevention services.

On September 29, the provider was hit by a ransomware attack that resulted in portions of its network being encrypted.

RBHA says it identified the incident on September 30 and immediately evicted the attackers from its network.

The threat actor, it says, potentially accessed personal information such as names, Social Security numbers, passport numbers, and financial account and health information.

“There is no definitive evidence that your personal information was accessed at this time. However, because an unknown actor gained access to our network, we are providing this notice out of an abundance of caution,” RBHA said in an incident notice (PDF) on its website.

Advertisement. Scroll to continue reading.

The mental health services provider told the US Department of Health and Human Services that 113,232 individuals were affected by the incident.

“We encourage you to remain vigilant against incidents of identity theft and fraud, to review your account statements, and to monitor your credit reports for suspicious activity,” RBHA told the impacted individuals.

While RBHA did not name the ransomware gang responsible for the attack, the Qilin group claimed the attack in mid-October, when it added the healthcare organization to its Tor-based leak site.

Qilin has since published 192 gigabytes of data (a total of over 393,000 files) allegedly stolen from RBHA.

Related: 700,000 Records Compromised in Askul Ransomware Attack

Related: Ransomware Payments Surpassed $4.5 Billion: US Treasury

Related: Inotiv Says Personal Information Stolen in Ransomware Attack

Related: Ransomware Attack Disrupts Local Emergency Alert System Across US

Related Content

Data Breaches

The private equity firm appears to have been targeted as part of a campaign focusing on major financial companies.

Data Breaches

The cybercrime gang has listed major companies such as Shell, Philips, Fiserv, Zebra, Mindray, and Largan Precision.

Data Breaches

The data breach was initially believed to affect roughly 350,000 people, but the HHS breach tracker shows a far bigger impact.

Data Breaches

Hackers stole names, addresses, phone numbers, Social Security numbers, and financial information from a third-party platform.

Data Breaches

Hackers used compromised credentials to access enterprise and personal tax-related data.

Data Breaches

Hackers exploited a vulnerability in the order-tracking function of a plugin to access SafePal customer information.

Data Breaches

The hackers published the allegedly stolen information, including names, addresses, email addresses, and phone numbers.

Data Breaches

The root cause of the incident is believed to be a compromised AWS access key that was exposed in publicly available JavaScript build artifacts.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version