On April 09, 2023, healthcare provider SkyFORS appeared on the leak site operated by the malas ransomware group. The listing states that internal files were exfiltrated during a ransomware attack that leveraged a Zimbra vulnerability. The entry does not disclose the number of affected individuals, the precise volume or types of records taken, or any ransom demand.
Watch SkyFORS
Get alerted the next time SkyFORS files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about SkyFORS’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Primary Disclosure Details
The malas leak site lists SkyFORS under the heading “defaulters” and claims the organization failed to meet the group’s demands. According to the posting, attackers gained initial access by exploiting an unpatched Zimbra collaboration suite vulnerability, then exfiltrated internal files before encrypting systems. The disclosure indicates that samples of the stolen data were published as proof, though the leak-site listing itself does not detail what categories of information were taken or how many records may be involved. No official breach notification from SkyFORS has surfaced publicly, leaving the exact scope of exposure unknown at this time.
Why This Matters for You and Your Family
When a healthcare organization’s internal files are stolen, the information often includes patient names, dates of birth, Social Security numbers, medical histories, insurance details, and contact information. Even without an exact count from the disclosure, any family that has used SkyFORS services could have sensitive personal and health data now in criminal hands. Medical records are especially damaging because they can be used for insurance fraud, prescription scams, or to impersonate you in government benefit programs. The uncertainty itself creates stress: you cannot easily know whether your family’s details are among the exfiltrated files.
Doxxing and Identity-Chain Risks
Stolen internal files frequently contain not only patient data but also employee directories, vendor contracts, and email correspondence that link names, addresses, phone numbers, and usernames. These fragments allow attackers to build identity chains that connect your healthcare records to social-media handles, gaming accounts, and family-member profiles. Once mapped, the information can fuel spear-phishing campaigns, account takeovers, or public doxxing. Credential leaks of this nature routinely cascade into children’s gaming accounts that reuse the same email or password, exposing younger family members to harassment or further compromise.