MedCenter Romania - 2 TB data - all of their data
by ddkdkdk343555 - Tuesday October 31, 2023 at 04:43 PM
#1
Their main website: https://medcenter.ro/

- From https://www.linkedin.com/company/medcenter
MEDCENTER is one of the top five suppliers of private medical services in Romania, both clinical and laboratory.
At a glance:
  o Started in 1998
  o Owns a network of over 40 medical centers, laboratories, blood-collection locations
  o Around 6.000.000 laboratory tests yearly
  o Around 50.000 patients yearly
  o Around 40.000 medical subscriptions sold
  o Over 500 private companies as customers
  o Quality Management System certified according to SR EN ISO 9001:2015 standard
  o Medcenter Laboratories are RENAR accredited, according to SR EN ISO 15189:2013 standard

Industry: Hospitals and Health Care
Company size: 201-500 employees
Headquarters: București, România
Type: Privately Held

-
I've successfully hacked their Active Directory environment, obtained the domain administrator role, access the Network Attached Storage (encrypted & removed all backups), access the database servers, app servers (encrypted & removed them all).

-
The content of the data is sql databases (mostly patients' data, patients' health history record), documents of patients' data & backup of important virtual machines

[Image: Kh76HWP.png]

-
Main website with the message telling they're under maintenance because of the hack

[Image: mMDVFMl.png]

[Image: xxUqZa7.png]

-
contact email for buying: ddkdkdk343555@proton.me
Reply
#2
(10-31-2023, 04:43 PM)ddkdkdk343555 Wrote: Their main website: https://medcenter.ro/

- From https://www.linkedin.com/company/medcenter
MEDCENTER is one of the top five suppliers of private medical services in Romania, both clinical and laboratory.
At a glance:
  o Started in 1998
  o Owns a network of over 40 medical centers, laboratories, blood-collection locations
  o Around 6.000.000 laboratory tests yearly
  o Around 50.000 patients yearly
  o Around 40.000 medical subscriptions sold
  o Over 500 private companies as customers
  o Quality Management System certified according to SR EN ISO 9001:2015 standard
  o Medcenter Laboratories are RENAR accredited, according to SR EN ISO 15189:2013 standard

Industry: Hospitals and Health Care
Company size: 201-500 employees
Headquarters: București, România
Type: Privately Held

-
I've successfully hacked their Active Directory environment, obtained the domain administrator role, access the Network Attached Storage (encrypted & removed all backups), access the database servers, app servers (encrypted & removed them all).

-
The content of the data is sql databases (mostly patients' data, patients' health history record), documents of patients' data & backup of important virtual machines

[Image: Kh76HWP.png]

-
Main website with the message telling they're under maintenance because of the hack

[Image: mMDVFMl.png]

[Image: xxUqZa7.png]

-
contact email for buying: ddkdkdk343555@proton.me

This looks really big
Reply
#3
(11-02-2023, 09:35 AM)johnsmith1924 Wrote:
(10-31-2023, 04:43 PM)ddkdkdk343555 Wrote: Their main website: https://medcenter.ro/

- From https://www.linkedin.com/company/medcenter
MEDCENTER is one of the top five suppliers of private medical services in Romania, both clinical and laboratory.
At a glance:
  o Started in 1998
  o Owns a network of over 40 medical centers, laboratories, blood-collection locations
  o Around 6.000.000 laboratory tests yearly
  o Around 50.000 patients yearly
  o Around 40.000 medical subscriptions sold
  o Over 500 private companies as customers
  o Quality Management System certified according to SR EN ISO 9001:2015 standard
  o Medcenter Laboratories are RENAR accredited, according to SR EN ISO 15189:2013 standard

Industry: Hospitals and Health Care
Company size: 201-500 employees
Headquarters: București, România
Type: Privately Held

-
I've successfully hacked their Active Directory environment, obtained the domain administrator role, access the Network Attached Storage (encrypted & removed all backups), access the database servers, app servers (encrypted & removed them all).

-
The content of the data is sql databases (mostly patients' data, patients' health history record), documents of patients' data & backup of important virtual machines

[Image: Kh76HWP.png]

-
Main website with the message telling they're under maintenance because of the hack

[Image: mMDVFMl.png]

[Image: xxUqZa7.png]

-
contact email for buying: ddkdkdk343555@proton.me

This looks really big

Yes, it's for sale
Reply
#4
any sample of patient's data ?
Reply
#5
(11-02-2023, 12:12 PM)johnsmith1924 Wrote: any sample of patient's data ?

I do not know about romanian language, but, this should be at first glance

[Image: sEdVUkx.png]

[Image: gL38OXS.png]
Reply
#6
how did you hack them ?
Reply
#7
(11-02-2023, 03:40 PM)johnsmith1924 Wrote: how did you hack them ?

I hacked their Active Directory environment.
Reply
#8
sample lab test of a patient

[Image: HclG5cq.png]
Reply
#9
(11-02-2023, 07:20 PM)ddkdkdk343555 Wrote:
(11-02-2023, 03:40 PM)johnsmith1924 Wrote: how did you hack them ?

I hacked their Active Directory environment.

any proofs beside databases ?
Reply
#10
Some screenshots of RAT's RDP seeing what they're doing.

- They discovered that there're some unusual RDPs, so, they call the IT staff (gpanaIT) to see windows logon event

[Image: 2d6ygsN.png]

- Use hmsuser (a super domain) doing his health admin job everyday

--> The softwares (infoworld (https://www.infoworld.com/ ???) ...) used for health system in romania are old as expected. I think they have internet connections with other government entities in romania, but did not check

[Image: qEOkJd4.png]

[Image: 7q4YMkM.png]

[Image: 4UxD91q.png]

[Image: 0hYJ6im.png]

[Image: fwF4Ga8.png]

[Image: fLuo6Yg.png]

[Image: H2e4BMu.png]

[Image: XAdUgJZ.png]
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  SELLING Africa ( Tunisia + Nigeria ) Data (Name+Email+Phone+Pays+Login+As) Bambi 3 2,339 7 hours ago
Last Post: Bambi
  VERIFIED Omnicuris.com Data Breach 888 1 301 Today, 12:50 AM
Last Post: 888
  SELLING Hasaki.vn Data Breach 888 1 236 Today, 12:49 AM
Last Post: 888
  VERIFIED The Lallantop Data Breach 888 1 248 Today, 12:48 AM
Last Post: 888
  SELLING Orul Tech Data Breach 888 1 123 Today, 12:04 AM
Last Post: 888

Forum Jump:


 Users browsing this thread: 1 Guest(s)