> ## Content Index
> Fetch the complete content index at: https://darkwebinformer.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# AdvaCare Dataset Claimed on Forum, 20,734 Timesheet Entries and 39 Staff Accounts
- URL: https://darkwebinformer.com/advacare-dataset-claimed-on-forum-20-734-timesheet-entries-and-39-staff-accounts/
- Published: 2026-09-09T19:39:11.000Z
- Updated: 2026-09-09T19:39:11.000Z
- Author: Dark Web Informer
- Tags: Data Breaches

Breach Report Switzerland Staff & Financial Data Database Dump 

## AdvaCare Dataset Claimed on Forum, 20,734 Timesheet Entries and 39 Staff Accounts

A forum actor posting as **DaOnlySpark** has published what they describe as a small dump of data belonging to **AdvaCare**, a Swiss healthcare consultancy focused on long-term care and nursing. According to the post, the dataset contains **20,734 timesheet entries, 4,683 tasks, 2,606 expense records, 732 projects and 39 staff accounts**. The actor claims the material includes **employee names, email addresses, hourly rates, billable hours by employee and task, expense amounts, tax and invoice references, project costs and internal cost centre information**. A visible staff sample is included in the post, while the download is hidden behind a forum reply requirement. The claim is **unverified**.

Severity HIGH 

[ ![WhiteIntel, dark web exposure monitoring](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/whiteintel_io_banner.jpg) ](https://whiteintel.io/?utm%5Fsource=darkwebinformer.com&utm%5Fmedium=referral&utm%5Fcampaign=whiteintel) 

Timesheets20,734

Tasks4,683

Expenses2,606

Staff accounts39

### ▣Post details

TargetAdvaCare

CountrySwitzerland

SectorHealthcare consultancy

ListingSmall database dump

Projects732

DownloadReply required to reveal

ObservedSep 9, 2026

ActorDaOnlySpark

### !What the post claims

- 20,734 timesheet entries
- 4,683 task records
- 2,606 expense records
- 732 projects
- 39 staff accounts
- Employee full names
- Employee email addresses
- Hourly rates
- Billable hours by employee and task
- Expense amounts
- Tax references
- Invoice references
- Project costs
- Internal cost centres
- Staff sample published in the thread
- Download hidden behind forum reply

### ◱Screenshot

[ ![Cybercrime forum post claiming a database dump belonging to Swiss healthcare consultancy AdvaCare, September 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/8432587962359829637852938765978623.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/8432587962359829637852938765978623.png) 

Forum post claiming a database dump belonging to AdvaCare, observed 9 September 2026.

### ☷Mapped techniques

The post does not describe how access was obtained or how the data left the environment. The entry below is inferred from the structure of the claimed dataset, not stated by the actor.

- Collection [T1213](https://attack.mitre.org/techniques/T1213/) Data from information repositories Inferred The claimed material groups structured timesheet, task, expense, project and staff-account records, which is consistent with data collected from an internal business information repository or application database.

### ⚠Potential impact

If authentic, the exposed staff information could support **targeted phishing, business email compromise and payroll or finance impersonation**, particularly because names and email addresses are paired with internal work and compensation details. The claimed **hourly rates, billable hours, expense amounts, invoice references, project costs and internal cost centres** could also reveal sensitive operational and financial information that may be useful for fraud or social engineering. The visible post describes staff, project, timesheet and expense data. **It does not claim patient or clinical records.**

### iStatus Unverified

The forum post includes record counts and a structured staff sample, but it provides **no explanation of how the data was obtained**, when the alleged access occurred, or whether the underlying archive is complete. The download itself is hidden and requires a reply to the thread before it can be viewed. Dark Web Informer has **not independently verified the dataset or the claimed record counts**.

Want everything on this breach? **Paid subscribers** get the full unredacted claim details and more. After subscribing, check out the [threat feed](https://darkwebinformer.com/threat-feed/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=advacare-2026-09-09&utm%5Fcontent=threat-feed) and search there for this alert.

[View pricing →](https://darkwebinformer.com/pricing?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=advacare-2026-09-09&utm%5Fcontent=pricing-button) 

[Dark Web Informer](https://darkwebinformer.com/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=advacare-2026-09-09&utm%5Fcontent=footer) // Threat Intelligence