Skip to content

Jinko Patient Records Published With Diagnoses and Private Messages

Breach Report France Patient Health Data Published Free

Jinko Patient Records Published With Diagnoses and Private Messages

A forum actor posting as DaOnlySpark has published 3.7 GB attributed to Jinko, a French cancer care support platform. The release is described as 85 database tables holding 883,178 rows, plus a file archive of 2,626 items. The patient side covers 3,552 accounts with email, name, phone, address and date of birth alongside a full clinical profile: cancer type, disease stage, metastasis and location, recurrence, current and previous treatments, medications, surgical and family history, and socio economic fields. Also present are free text nurse and practitioner notes, 20,635 private messages, quality of life questionnaires, symptom and weight tracking, and 142 named doctors with contact details. The actor states 1,957 of the stored files are patient health documents. The claim is unverified.

Patient accounts3,552
Rows883,178
Health files1,957
ActorDaOnlySpark

Post details

TargetJinko
CountryFrance
SectorCancer care support
ListingFree, reply to unlock
Volume3.7 GB, 85 tables
Stated sourceNot described
Observed
ActorDaOnlySpark

!What the post claims

  • 3.7 GB across 85 tables
  • 883,178 rows total
  • 2,626 stored files
  • 1,957 patient health documents
  • 3,552 patient accounts
  • 188,023 change log entries
  • Names, emails and phones
  • Addresses and dates of birth
  • Cancer type and stage
  • Metastasis and location
  • Recurrence status
  • Current and past treatments
  • Medications and pathologies
  • Surgical and family history
  • Socio economic fields
  • Free text clinical notes
  • 20,635 private messages
  • Quality of life questionnaires
  • Symptom and weight tracking
  • 142 named doctors with contacts

Screenshots

Forum post publishing Jinko data, observed 7 September 2026.

Mapped techniques

The post describes no intrusion method. All entries are inferred from the artefacts, not stated.

  • Initial access T1190 Exploit public facing application Inferred A complete export of both the document database and the file storage of a mobile application backend is more characteristic of permissive access rules than of a server intrusion. No flaw is named.
  • Collection T1213 Data from information repositories Inferred Eighty five collections were exported together, including change logs and message history rather than only current records.
  • Collection T1530 Data from cloud storage Inferred The file archive is itemised by media type and by application area, which indicates the storage bucket was enumerated in full alongside the database.

Potential impact

This is identified cancer patients tied to diagnosis, stage, metastasis, treatment and family history, which is the most protected category of personal data there is, and disclosure of it reaches employment, insurance and family life in ways that cannot be undone. The free text is worse than the fields: nurse and practitioner notes, thousands of private messages and assistant conversations record what people said in confidence during the hardest period of their lives, including things they may not have told their families. The clinician side compounds it, since named oncologists with direct contact details appear alongside the patients they treat, which exposes the care relationship itself.

iStatus Unverified

The inventory is unusually granular, with per table row counts, file counts broken down by format and application area, and demographic splits, which is the work of someone who has parsed the export rather than described it from memory. Nothing is said about how it was obtained, and the platform stack named in the post points more towards a configuration failure than an intrusion, though that remains inference. The account is established with a paid rank and the data is released free, so there is no price being defended. Dark Web Informer has not retrieved the files and is not linking them, and Jinko has not publicly addressed the claim.

Dark Web Informer // Threat Intelligence

Latest