> ## Content Index
> Fetch the complete content index at: https://darkwebinformer.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# Saudi Military Hospital Hack Claim Includes Patient and Staff Samples
- URL: https://darkwebinformer.com/saudi-military-hospital-hack-claim-includes-patient-and-staff-samples/
- Published: 2026-09-28T17:06:18.000Z
- Updated: 2026-09-28T17:06:18.000Z
- Author: Dark Web Informer
- Tags: Data Breaches

Data Exposure Report 🇸🇦Saudi Arabia Military Hospital Patient and Staff Data Hack Claim Unverified 

## Saudi Military Hospital Hack Claim Includes Patient and Staff Samples

Claimed scopeThousands

Sample materialPatient and staff

Dashboard users1,105

Claimed accessHospital systems

Severity HIGH 

### Overview

A poster using the handle **"UWAYS"**, writing on behalf of Uways Qarani, claims to have penetrated systems associated with **Prince Sultan Military Medical City (PSMMC)**, also referred to in the post as Riyadh Military Hospital. The group claims it obtained information on thousands of Saudi military personnel, as well as patient and staff records, treatment details and identity documents.

Six supplied captures show the statement and purported samples: a patient referral table, hospital location and laboratory lists, a staff roster, identity card thumbnails, and hospital administration screens. One sample dashboard names **Prince Sultan Armed Forces Hospital Madinah**, a different facility label from the Riyadh institution in the claim. **The intrusion, origin, completeness and scale of the data have not been independently verified.**

### Post details

Organization namedPrince Sultan Military Medical City

Country🇸🇦 Saudi Arabia

Location claimedRiyadh

Facility in dashboard samplePrince Sultan Armed Forces Hospital Madinah

Poster"UWAYS"

Group namedUways Qarani

Claimed volumeThousands of personnel records, no exact count

Dashboard figure1,105 users shown in a sample interface

Post date shownSep 28, 2026

### What the post claims

- Complete control of the named military hospital claimed
- Information on thousands of military personnel claimed extracted
- Medical records and treatment files claimed
- Patient and staff lists claimed available
- Military identity cards claimed available
- Patient referral table shown
- Staff roster with roles and contact fields shown
- Hospital location and department metadata shown
- Laboratory test catalog shown
- Identity document thumbnails shown
- Hospital admin dashboard screenshots shown
- Data advertised for download on the group site

The post claims access to a Riyadh military hospital. A sample dashboard instead names a Madinah facility. The screenshots do not establish that either institution was compromised or that the claimed download contains all the categories described.

Sponsored

[ ![WhiteIntel, dark web exposure monitoring](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/whiteintel_io_banner.jpg) ](https://whiteintel.io/?utm%5Fsource=darkwebinformer.com&utm%5Fmedium=referral&utm%5Fcampaign=whiteintel)

### Screenshots

[Screenshot 1Source screenshot![Post claiming access to a Saudi military hospital, followed by a purported patient referral table](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/982735692873568972635896723598751.png) ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/982735692873568972635896723598751.png) [Screenshot 2Source screenshot![Continuation of the referral sample, hospital location list and beginning of a laboratory catalog](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/982735692873568972635896723598752.png) ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/982735692873568972635896723598752.png) [Screenshot 3Source screenshot![Continuation of the laboratory catalog and a purported hospital employee roster](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/982735692873568972635896723598753.png) ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/982735692873568972635896723598753.png) [Screenshot 4Source screenshot![Identity document thumbnail gallery and the upper portion of an identity card sample](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/982735692873568972635896723598754.png) ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/982735692873568972635896723598754.png) [Screenshot 5Source screenshot![Continuation of an identity card sample and purported hospital user administration screens](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/982735692873568972635896723598755.png) ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/982735692873568972635896723598755.png) [Screenshot 6Source screenshot![Continuation of a hospital administration dashboard and a master data portal sample](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/982735692873568972635896723598756.png) ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/982735692873568972635896723598756.png) 

Six supplied captures from one post. The visible samples include personal and medical information; individual names, patient identifiers, contact details and document numbers are not repeated in this report. The dashboard count refers to an interface shown in the sample, not a verified count of affected people.

### IOCs & contact identifiers

Identifiers visible in the listing. These support correlation and do not independently establish access to the named institutions.

| Type             | Identifier     | Source       |
| ---------------- | -------------- | ------------ |
| Poster           | UWAYS          | Screenshot 1 |
| Group website    | uways\[.\]to   | Screenshot 1 |
| Telegram contact | @UWAYS\_QARANI | Screenshot 1 |

The website and Telegram handle are advertised contact points in the post; the screenshots do not establish who controls them. No Tox ID, Session ID, malware hash or attacker-controlled IP address is visible. Patient, staff and identity-document identifiers shown in the purported samples are not included in this table. URLs to any data will always be blurred out, but are available to subscribers on the threat feed or ransomware feed.

### Mapped techniques

**Claimed** identifies behavior explicitly described by the actor. **Inferred** identifies an analytical mapping supported by the supplied material. Neither label means the activity has been independently verified.

- Collection [T1213.006](https://attack.mitre.org/techniques/T1213/006/) [Data from Information Repositories: Databases](https://attack.mitre.org/techniques/T1213/006/) Inferred The group claims to have extracted hospital personnel and medical records. The tabular and administrative samples are consistent with stored records, but do not show how they were obtained.

### Potential impact

If authentic, disclosure of patient referrals, medical details, staff rosters and identity cards could expose **sensitive health and identity information**. The claim also references military personnel and movements, which could create further risks if supported by the underlying material. The visible dashboard's **1,105 users** is a count displayed in that interface, **not a verified breach or victim count**.

### Status Unverified

Dark Web Informer has **not independently verified** the claimed intrusion, control of hospital systems, number of affected people, or authenticity and source of the records. The visible samples contain a Madinah facility label while the post names PSMMC in Riyadh, and that relationship is unresolved. Screenshots of records and application interfaces do not demonstrate the attack path or current control of a live system. No independent response from the named hospital or Saudi authorities is present in the supplied material.

Want everything on this threat? **Paid subscribers** get the full unredacted claim details and more. After subscribing, check out the [threat feed](https://darkwebinformer.com/threat-feed/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=saudi-military-hospital-hack-claim-2026-09-28&utm%5Fcontent=threat-feed) and search there for this alert.

[View pricing →](https://darkwebinformer.com/pricing?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=saudi-military-hospital-hack-claim-2026-09-28&utm%5Fcontent=pricing-button) 

[Dark Web Informer](https://darkwebinformer.com/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=saudi-military-hospital-hack-claim-2026-09-28&utm%5Fcontent=footer)