> ## Content Index
> Fetch the complete content index at: https://darkwebinformer.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# Alleged Breach of Therapeutes Exposes 71,500 Patient Records and 199,000 Therapy Appointments From French Mental Health Platform
- URL: https://darkwebinformer.com/alleged-breach-of-therapeutes-exposes-71-500-patient-records-and-199-000-therapy-appointments-from-french-mental-health-platform/
- Published: 2026-03-13T16:21:43.000Z
- Updated: 2026-03-13T16:21:43.000Z
- Author: Dark Web Informer
- Tags: Data Breaches

Dark Web Informer - Cyber Threat Intelligence 

# Alleged Breach of Therapeutes.com Exposes 71,500 Patient Records and 199,000 Therapy Appointments From French Mental Health Platform

March 13, 2026 - 9:29:28 AM UTC 

France 

Healthcare / Mental Health 

Standalone API Access Now Available High-volume threat-intelligence data, automated ingestion endpoints, ransomware feeds, IOC data, and more. 

[ View API](https://darkwebinformer.com/api-details/) 

 Unlock Exclusive Cyber Threat Intelligence

Powered by DarkWebInformer.com

Stay ahead of cyber threats with real-time breach tracking, expert analysis, and high quality evidence - built for security professionals, researchers, journalists, and everyday people who take their privacy seriously.

[ Subscribe Now](https://darkwebinformer.com/pricing) 

## Quick Facts

Date & Time 2026-03-13 09:29:28 UTC 

Threat Actor HexDex 

Victim Therapeutes.com 

Industry Healthcare / Mental Health 

Category Data Breach 

Alleged Records 71,502 Patients 

Appointments 199,697 

Unique Emails 95,985 

Unique Phones 97,518 

Price Make Offer 

Network Open Web 

Country France 

##  Incident Overview

A threat actor going by HexDex claims to be selling sensitive data from Therapeutes.com, a French online platform that has been connecting users with licensed therapists and mental health professionals since 2013\. The platform allows people to find, book, and attend therapy sessions either in person or through video calls, meaning the underlying database contains deeply personal information about individuals seeking mental health support.

  
What makes this breach particularly concerning is the nature of the data involved. This isn't just emails and phone numbers, the listing explicitly mentions therapy appointment records with consultation and reason fields, which would reveal why individuals sought therapy in the first place. The actor provided the following breakdown:

- **Patient Records** \- 71,502 patients with associated personal information.
- **Appointment Data** \- 199,697 appointments total, including 56,225 entries with a "consultation" field and 23,492 entries with a "reason" field describing the purpose of the therapy visit.
- **Contact Data** \- 95,985 unique email addresses and 97,518 unique phone numbers.
- **Government Emails** \- 27 gouv.fr email addresses were identified in the dataset, indicating some French government employees are among those affected.
- **Samples** \- The actor provided proof links and a 500-line sample to demonstrate the data's authenticity.
  
The actor is accepting offers rather than listing a fixed price, and recommends using escrow for secured transactions. Given that this involves healthcare data protected under the EU's GDPR and potentially France's additional health data regulations, the exposure of therapy reasons and consultation details represents a severe privacy risk for affected individuals.

##  Compromised Data Categories

 Patient Records  Therapy Appointment Details  Consultation Fields  Therapy Reason / Purpose  Email Addresses  Phone Numbers  Government Employee Emails (gouv.fr) 

##  Image Preview

[![Forum post by HexDex selling Therapeutes.com patient data including 71,502 patients, 199,697 appointments, and therapy consultation details](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/82164831086980798505.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/82164831086980798505.png) 

##  Claim URL

Subscriber Access Required The original listing URL and unredacted claim images are available on the Threat Feed and Ransomware Feed for paid subscribers. 

[ Subscribe](https://darkwebinformer.com/pricing) 

##  MITRE ATT&CK Mapping

[ T1190 Exploit Public-Facing Application Targets vulnerabilities in internet-facing web applications to gain unauthorized access to backend databases and patient records. ](https://attack.mitre.org/techniques/T1190/) [ T1213 Data from Information Repositories Extracts structured data from application databases, pulling patient records, appointment histories, and consultation details from the platform's backend. ](https://attack.mitre.org/techniques/T1213/) [ T1530 Data from Cloud Storage Accesses cloud-hosted databases or storage buckets containing user data, appointment records, and sensitive health information. ](https://attack.mitre.org/techniques/T1530/) [ T1589.002 Gather Victim Identity: Email Addresses Collects unique email addresses from the breached database, including government employee accounts (gouv.fr), for resale or targeted attacks. ](https://attack.mitre.org/techniques/T1589/002/) [ T1567 Exfiltration Over Web Service Uses web platforms and forums to advertise, sample, and distribute stolen healthcare data to potential buyers. ](https://attack.mitre.org/techniques/T1567/) [ T1078 Valid Accounts Uses compromised or stolen credentials to gain access to the platform's administrative systems or database infrastructure. ](https://attack.mitre.org/techniques/T1078/) 

Dark Web Informer © 2026 | Cyber Threat Intelligence  
[DarkWebInformer.com](https://darkwebinformer.com/)