Skip to content

AdvaCare Dataset Claimed on Forum, 20,734 Timesheet Entries and 39 Staff Accounts

Breach Report Switzerland Staff & Financial Data Database Dump

AdvaCare Dataset Claimed on Forum, 20,734 Timesheet Entries and 39 Staff Accounts

A forum actor posting as DaOnlySpark has published what they describe as a small dump of data belonging to AdvaCare, a Swiss healthcare consultancy focused on long-term care and nursing. According to the post, the dataset contains 20,734 timesheet entries, 4,683 tasks, 2,606 expense records, 732 projects and 39 staff accounts. The actor claims the material includes employee names, email addresses, hourly rates, billable hours by employee and task, expense amounts, tax and invoice references, project costs and internal cost centre information. A visible staff sample is included in the post, while the download is hidden behind a forum reply requirement. The claim is unverified.

Timesheets20,734
Tasks4,683
Expenses2,606
Staff accounts39

Post details

TargetAdvaCare
CountrySwitzerland
SectorHealthcare consultancy
ListingSmall database dump
Projects732
DownloadReply required to reveal
Observed
ActorDaOnlySpark

!What the post claims

  • 20,734 timesheet entries
  • 4,683 task records
  • 2,606 expense records
  • 732 projects
  • 39 staff accounts
  • Employee full names
  • Employee email addresses
  • Hourly rates
  • Billable hours by employee and task
  • Expense amounts
  • Tax references
  • Invoice references
  • Project costs
  • Internal cost centres
  • Staff sample published in the thread
  • Download hidden behind forum reply

Screenshot

Forum post claiming a database dump belonging to AdvaCare, observed 9 September 2026.

Mapped techniques

The post does not describe how access was obtained or how the data left the environment. The entry below is inferred from the structure of the claimed dataset, not stated by the actor.

  • Collection T1213 Data from information repositories Inferred The claimed material groups structured timesheet, task, expense, project and staff-account records, which is consistent with data collected from an internal business information repository or application database.

Potential impact

If authentic, the exposed staff information could support targeted phishing, business email compromise and payroll or finance impersonation, particularly because names and email addresses are paired with internal work and compensation details. The claimed hourly rates, billable hours, expense amounts, invoice references, project costs and internal cost centres could also reveal sensitive operational and financial information that may be useful for fraud or social engineering. The visible post describes staff, project, timesheet and expense data. It does not claim patient or clinical records.

iStatus Unverified

The forum post includes record counts and a structured staff sample, but it provides no explanation of how the data was obtained, when the alleged access occurred, or whether the underlying archive is complete. The download itself is hidden and requires a reply to the thread before it can be viewed. Dark Web Informer has not independently verified the dataset or the claimed record counts.

Dark Web Informer // Threat Intelligence

Latest