🚨 CYBER INTELLIGENCE ALERT: POSSIBLE MEDICAL DATA LEAK - QATAR 🇶🇦
⚠️ CRITICAL THREAT: ACTOR "S-ROOT" RELEASES 12 GB OF "AMAN HOSPITAL" DATABASES
[STATUS: FILES PUBLICLY RELEASED / PENDING INDEPENDENT ASSESSMENT, NOT YET VERIFIED]
The threat actor identified by the alias S-Root has announced and carried out the public release of a batch of databases belonging to Aman Hospital (amanhospital. org), a prominent and modern luxury private medical institution located in Doha, Qatar. The attacker has fragmented and published the data for free through direct downloads split into multiple parts within their distribution channels.
🎯 Entity: Aman Hospital (Doha, Qatar).
👤 Threat Actor: S-Root
📂 Data Volume: 12 GB net, structured in individual compressed (.zip) files of approximately 1 GB each.
⚠️ Verification Status: SAMPLES RELEASED / NOT INDEPENDENTLY EVALUATED. While the download files are active and structured under an explicit corporate naming convention (aman_0xshadow_part_XX.zip), the exact internal content and the time frame for the clinical records have not yet been thoroughly analyzed or validated by independent security laboratories.
📂 ANALYSIS OF THE ACCESS SURFACE AND ANTICIPATED RISK
Given the operational nature of Aman Hospital (an institution with over 100 beds and more than 20 complex medical specialties), the 12 GB volume of relational data is expected to contain critical Protected Health Information (PHI) and Personally Identifiable Information (PII):
📋 Medical Records and Histories: Diagnoses, emergency room admissions, clinical specialty assignments, laboratory results, allergies, and medication prescriptions for local and international patients. 🆔 Patient Identification Information: Full names, civil identification numbers (Qatar ID), passport details, residential addresses, contact phone numbers, and private health insurance records.
💼 Internal Information and Personnel Data: Operational data regarding medical staff, nursing shifts, institutional corporate email accounts, payroll records, and Hospital Information System (HIS) software configurations.
🛡️ MITIGATIONS AND EMERGENCY TECHNICAL RECOMMENDATIONS
🔒 Isolation and Forensic Analysis: The IT and cybersecurity team at Aman Hospital is urged to execute an immediate incident response process to determine whether any mass data exfiltrations or leaks occurred on their cloud servers or backup storage systems over the past few days.
⚠️ Complete HIS Credential Rotation: Forcibly reset all passwords and access keys for Hospital Information Systems (HIS), databases, and online medical portals to mitigate persistent access by intruders.
🔍 Audit of Compromised Accounts: Evaluate API keys and integration tokens linked to telemedicine providers or external appointment portals that communicate directly with central data repositories.
⚡ MONITORING AND EVALUATION
🌐 Intelligence System:
analyzer.vecert.io
🛡️ Quickly assess your website's security at:
monitor.vecert.io/
#CyberSecurity #Qatar #AmanHospital #DataLeak #MedicalRecords #SRoot #Doha #PHI #Infosec #ThreatIntelligence #CyberAlert #VECERT #HospitalHack