DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

MPOWERHealth victim of cyberattack; protected health information involved (1)

Posted on August 21, 2025August 21, 2025 by Dissent

Today’s post is a reminder that purging files is helpful, but remember to empty the recycle bin.

A listing on WorldLeaks’ darkweb leak site yesterday claims that WorldLeaks acquired 1.5 TB of data from MPOWERHealth, comprising 1,622,547 files.

MPOWERHealth describes itself as providing innovative healthcare solutions, specializing in Intraoperative Neuromonitoring (IONM), Surgical Assist, and Care Management. It is headquartered in Addison, Texas.

DataBreaches was able to preview part of what was tagged as an incomplete leak. The available files revealed internal files from one drive. Of greater concern, there were a lot of files with protected health information (PHI) involving health insurance claims and explanation of benefits (EOBs). Those files were sitting, intact and unencrypted, in the Recycle Bin.

In addition to all the health insurance-related files, DataBreaches also noted a file with logins and passwords and files detailing the entity’s cyberinsurance policy. DataBreaches does not know if WorldLeaks had found the policy or read it before setting the amount of their demand, and does not know how much WorldLeaks demanded.

When asked, a WorldLeaks spokesperson informed DataBreaches that they gained access to MPOWER Health on June 29, and there were some negotiations:

They were in touch with us. Their last message was: “We apologize for the delay, there have been some internal conflict that needed to be resolved before making any decisions. Additionally, there are significant concerns regarding the current price point. Is your organization willing to be flexible with the price before moving forward?”

And they are gone.

According to their answer to a follow-up inquiry, MPOWERHealth stopped responding after WorldLeaks answered their query about flexibility by stating that they needed to pay the full price. “They didn’t even argue,” the spokesperson stated.

DataBreaches emailed MPOWERHealth to ask about the incident and their response, but has received no reply to two email requests.

The amount of data and number of files was updated post-publication after WorldLeaks leaked all of the data. The full leak also contained many more files involving internal documents and insurance billing-related files.

Category: Breach IncidentsHealth Data

Post navigation

← Noah Urban aka “King Bob” of Scattered Spider, sentenced to 10 years in prison, $13 million restitution
Intel Websites Compromised, Allowing Hackers Access to Employee and Confidential Data →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Washington Post hack exposes personal data of John Bolton, almost 10,000 others
  • Draft UK Cyber Security and Resilience Bill Enters UK Parliament
  • Suspected Russian hacker reportedly detained in Thailand, faces possible US extradition
  • Did you hear the one about the ransom victim who made a ransom installment payment after they were told that it wouldn’t be accepted?
  • District of Massachusetts Allows Higher-Ed Student Data Breach Claims to Survive
  • End of the game for cybercrime infrastructure: 1025 servers taken down
  • Doctor Alliance Data Breach: 353GB of Patient Files Allegedly Compromised, Ransom Demanded
  • St. Thomas Brushed Off Red Flags Before Dark-Web Data Dump Rocks Houston
  • A Wiltshire police breach posed possible safety concerns for violent crime victims as well as prison officers
  • Amendment 13 is gamechanger on data security enforcement in Israel

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Maryland Privacy Crackdown Raises Bar for Disclosure Compliance
  • Lawmakers Warn Governors About Sharing Drivers’ Data with Federal Government
  • As shoplifting surges, British retailers roll out ‘invasive’ facial recognition tools
  • Data broker Kochava agrees to change business practices to settle lawsuit
  • Amendment 13 is gamechanger on data security enforcement in Israel

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net
Security Issue: security[at]databreaches.net
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: +1 516-776-7756
DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.