In February this year, MacKay Memorial Hospital—one of Taiwan’s leading medical centers—was hit by the ransomware group “Crazy Hunter,” causing widespread outages across outpatient systems and disrupting patient healthcare services.

Although domestic cybersecurity specialists swiftly contained several stages of the cyberattack, reports surfaced that up to 16.6 million patient records had been exfiltrated and listed for sale on dark web marketplaces with an asking price of $100,000 USD (approximately NT$3.28 million).

The breached dataset reportedly spans multiple branches, including Taipei MacKay, Taipei Children’s Hospital, Tamsui MacKay, Hsinchu MacKay, Hsinchu Children’s Hospital, and Taichung clinics. Compromised records allegedly encompass patient names, national identification numbers, phone numbers, home addresses, medical histories, and diagnostic reports, totaling over 32.8 GB in archive volume.

Dark Web Sale: Fraud Syndicates Move In

According to statements posted by threat actors on dark web forums, an anonymous buyer believed to represent a transnational fraud syndicate successfully acquired the patient database for the requested $100,000. This indicates that private records belonging to millions of citizens may now reside directly in the hands of criminal organizations.

This development places affected patients and their families at severe risk, because scammers can weaponize granular clinical histories to craft hyper-personalized scams that victims find nearly impossible to detect.

6 Deceptive Scams to Watch Out For

With sensitive patient credentials and confidential health diagnoses leaked, fraud syndicates are expected to deploy the following six primary deception schemes:

1. Fake Medical Fee Collections

Scammers impersonating hospital administrative staff call patients or relatives, claiming discrepancies in health insurance claims or unpaid surgical balances, urging immediate wire transfers to designated accounts. With accurate patient admission details at their fingertips, fraudsters can effortlessly establish credibility and extract significant financial sums.

2. Fraudulent Medication and Therapy Schemes

Exploiting chronic condition histories, criminals masquerade as clinical specialists peddling “exclusive custom formulas” or “miracle therapeutics,” pressuring anxious patients into purchasing unregulated, ineffective concoctions. This harms both the victim’s wallet and their physical wellbeing.

3. Emergency Relative Impersonation

Armed with precise familial and hospital encounter records, fraudsters contact elderly family members claiming their relative suffered an acute medical emergency requiring immediate upfront deposits for life-saving surgery. Under panic, seniors frequently authorize wire transfers before verifying the facts.

4. Identity Theft for Loans and Insurance Claims

Perpetrators may exploit stolen IDs and forged medical histories to file fraudulent insurance compensation claims or open unauthorized online credit lines, damaging the victim’s credit profile and entangling them in protracted legal disputes.

5. Spear Phishing Campaigns

Criminals send spoofed hospital SMS notifications or emails stating, “Your recent health screening showed critical anomalies. Click here to view your complete diagnostic report.” Clicking the link directs victims to credential-harvesting phishing portals designed to compromise mobile banking tokens and credit card details.

6. Secondary Resale across Black Markets

Databases of this scale are routinely repackaged and resold among underground lead brokers and boiler-room call centers, resulting in non-stop harassment, nuisance calls, and recurring scam attempts.

5 Practical Defense Measures for Patients

To guard against malicious exploitation following such systemic healthcare breaches, citizens should adhere to five golden rules:

  • Verify Independently: Never act directly upon unverified incoming calls. Hang up and dial the official hospital switchboard listed on formal documents.
  • Do Not Click Unverified Links: Treat all unsolicited SMS and email alerts containing medical URLs with caution. Inspect test results exclusively through official hospital mobile apps or portal logins.
  • Stay Vigilant Against Fund Transfer Demands: Hospitals never mandate wire transfers via informal phone instructions or personal digital payment apps.
  • Warn Vulnerable Family Members: Educate elderly relatives that medical institutions do not demand expedited wire transfers over phone calls.
  • Regularly Audit Financial and Credit Activity: Periodically check banking notifications and credit bureau records to identify unauthorized loan inquiries or fraudulent filings immediately.

Institutional and Government Imperatives

This incident underscores severe vulnerabilities in healthcare information security architectures. Supervisory authorities must demand concrete interventions:

  1. Systemic Hardening: Enforce end-to-end data encryption at rest and in transit, multi-factor authentication (MFA), and zero-trust segmentation.
  2. Staff Training: Mitigate social engineering risks through mandatory phishing simulations and access-control reviews.
  3. Transparent Breach Notification Protocols: Mandate immediate disclosure to impacted individuals whenever private records are compromised, rather than leaving victims unaware.
  4. Substantial Penalties for Non-Compliance: Establish robust financial liabilities for healthcare institutions that fail to maintain basic cyber hygiene.
  5. Victim Redress Mechanisms: Assist affected citizens in securing compensation and identity-protection coverage against potential damages.

Summary

Medical records are far more than private files—they are high-value weapons in the hands of sophisticated scammers. Maintaining proactive skepticism toward unexpected messages and securing personal data remains your first line of defense.

✦ Independent Journalism · Reader Support ✦

Support Independent Perspectives & In-Depth Insights

Every thoughtful analysis and candid critique comes from our dedication to truth and quality. We choose not to follow sensational algorithms or clickbait headlines.

Sustaining independent research requires reader support. Make a one-time or monthly contribution, securely processed by Google.

Payments secured by Google · Manage or cancel anytime in your Google Account