Skip to content

Saudi Military Hospital Hack Claim Includes Patient and Staff Samples

Data Exposure Report 🇸🇦Saudi Arabia Military Hospital Patient and Staff Data Hack Claim Unverified

Saudi Military Hospital Hack Claim Includes Patient and Staff Samples

Claimed scopeThousands
Sample materialPatient and staff
Dashboard users1,105
Claimed accessHospital systems

A poster using the handle "UWAYS", writing on behalf of Uways Qarani, claims to have penetrated systems associated with Prince Sultan Military Medical City (PSMMC), also referred to in the post as Riyadh Military Hospital. The group claims it obtained information on thousands of Saudi military personnel, as well as patient and staff records, treatment details and identity documents.

Six supplied captures show the statement and purported samples: a patient referral table, hospital location and laboratory lists, a staff roster, identity card thumbnails, and hospital administration screens. One sample dashboard names Prince Sultan Armed Forces Hospital Madinah, a different facility label from the Riyadh institution in the claim. The intrusion, origin, completeness and scale of the data have not been independently verified.

Post details

Organization namedPrince Sultan Military Medical City
Country🇸🇦 Saudi Arabia
Location claimedRiyadh
Facility in dashboard samplePrince Sultan Armed Forces Hospital Madinah
Poster"UWAYS"
Group namedUways Qarani
Claimed volumeThousands of personnel records, no exact count
Dashboard figure1,105 users shown in a sample interface
Post date shown

What the post claims

  • Complete control of the named military hospital claimed
  • Information on thousands of military personnel claimed extracted
  • Medical records and treatment files claimed
  • Patient and staff lists claimed available
  • Military identity cards claimed available
  • Patient referral table shown
  • Staff roster with roles and contact fields shown
  • Hospital location and department metadata shown
  • Laboratory test catalog shown
  • Identity document thumbnails shown
  • Hospital admin dashboard screenshots shown
  • Data advertised for download on the group site

The post claims access to a Riyadh military hospital. A sample dashboard instead names a Madinah facility. The screenshots do not establish that either institution was compromised or that the claimed download contains all the categories described.

Screenshots

Six supplied captures from one post. The visible samples include personal and medical information; individual names, patient identifiers, contact details and document numbers are not repeated in this report. The dashboard count refers to an interface shown in the sample, not a verified count of affected people.

IOCs & contact identifiers

Identifiers visible in the listing. These support correlation and do not independently establish access to the named institutions.

TypeIdentifierSource
PosterUWAYSScreenshot 1
Group websiteuways[.]toScreenshot 1
Telegram contact@UWAYS_QARANIScreenshot 1

The website and Telegram handle are advertised contact points in the post; the screenshots do not establish who controls them. No Tox ID, Session ID, malware hash or attacker-controlled IP address is visible. Patient, staff and identity-document identifiers shown in the purported samples are not included in this table. URLs to any data will always be blurred out, but are available to subscribers on the threat feed or ransomware feed.

Mapped techniques

Claimed identifies behavior explicitly described by the actor. Inferred identifies an analytical mapping supported by the supplied material. Neither label means the activity has been independently verified.

Potential impact

If authentic, disclosure of patient referrals, medical details, staff rosters and identity cards could expose sensitive health and identity information. The claim also references military personnel and movements, which could create further risks if supported by the underlying material. The visible dashboard's 1,105 users is a count displayed in that interface, not a verified breach or victim count.

Status Unverified

Dark Web Informer has not independently verified the claimed intrusion, control of hospital systems, number of affected people, or authenticity and source of the records. The visible samples contain a Madinah facility label while the post names PSMMC in Riyadh, and that relationship is unresolved. Screenshots of records and application interfaces do not demonstrate the attack path or current control of a live system. No independent response from the named hospital or Saudi authorities is present in the supplied material.

Dark Web Informer

Latest