Get Your Free Report
Start for Free
SOCRadar® Cyber Intelligence Inc. | Alleged Healthcare, Military, RDP, SEP Tlaxcala, and GulfJobs Data Leaks
Jul 27, 2026
5 Mins Read
Moon

Alleged Healthcare, Military, RDP, SEP Tlaxcala, and GulfJobs Data Leaks

SOCRadar Dark Web Team identified several new underground posts involving alleged healthcare data exposure, military infrastructure compromise, initial access sales, and government employee data leaks. The findings include a claimed Transtreme breach affecting HealthNet-CMC and Aetna-CA patient records, a leak tied to Indonesian military infrastructure, an RDP access listing for an Indonesian technology/SaaS company, an alleged SEP Tlaxcala employee medical records leak, and a claimed GulfJobs.com candidate database exposure.

Receive a Free Dark Web Report for Your Organization:

Alleged Transtreme Patient Data Breach is Detected

Alleged Transtreme Patient Data Breach is Detected

SOCRadar Dark Web Team detected a threat actor post claiming a breach of Transtreme / HealthNet-CMC / Aetna-CA data. The actor, operating under the name The Crypt Apostles, claimed to hold 1.16 million unique patient records and threatened to sell the data if Transtreme did not contact them or pay the ransom.

The listing claimed the exposed data includes patient PII and healthcare-related identifiers, including names, dates of birth, addresses, phone numbers, Medicare Beneficiary Identifiers, insurance policy details, GPS coordinates, and primary care physician information. If authentic, this type of exposure creates a serious risk of identity theft, medical fraud, and targeted scams against patients, especially given the healthcare and elderly population context.

Alleged Indonesian Military Infrastructure Leak is Detected

Alleged Indonesian Military Infrastructure Leak is Detected

SOCRadar Dark Web Team detected a post claiming a compromise of Indonesian military .mil.id infrastructure, including database exports and administrative credentials. The actor claimed access to the mabesad.mil.id server and shared system information suggesting root-level access, along with exported databases and WordPress credential samples.

The post referenced multiple hosted military subdomains and claimed exposure of configuration details, database exports, and administrative login data. If valid, this could allow unauthorized changes to official military web assets, credential reuse attacks, defacement, malware placement, or deeper follow-on compromise across shared infrastructure.

Alleged RDP Access to Indonesian Technology Firm is Detected

Alleged RDP Access to Indonesian Technology Firm is Detected

SOCRadar Dark Web Team detected an initial access broker post advertising alleged RDP access to a technology/SaaS company in Indonesia. The listing described the target as a large enterprise with more than $5B in revenue, around 1,000 hosts, and SYSTEM-level privileges.

The actor also claimed that no AV or EDR was detected in the environment, which would make the access more attractive for ransomware operators or other threat actors seeking persistence and lateral movement. Even though the organization was not named, a valid RDP foothold with high privileges can quickly become a path to data theft, ransomware deployment, or long-term intrusion.

Alleged SEP Tlaxcala Employee Medical Records Leak is Detected

Alleged SEP Tlaxcala Employee Medical Records Leak is Detected

SOCRadar Dark Web Team detected a post by Hackero$ Crew claiming a breach involving the Secretariat of Public Education in Tlaxcala, Mexico. The leaked dataset was described as containing employee data from a portal used to manage private employee documentation, with records spanning 2012 to 2026.

The actor claimed the data includes full names, RFC tax identifiers, email addresses, hashed passwords, and medical records, including diagnoses and treatment-related details. This makes the leak especially sensitive, as it combines personal identifiers, credentials, and health information that could be used for identity theft, account takeover, or targeted extortion.

Alleged GulfJobs.com Candidate Database Leak is Detected

Alleged GulfJobs.com Candidate Database Leak is Detected

SOCRadar Dark Web Team detected a post advertising an alleged dataset from GulfJobs.com, claiming approximately 872,000 records tied to recruitment and candidate information. The actor described the data as covering contact information, candidate profiles, and job application details.

The claimed exposed fields include names, email addresses, mobile and landline numbers, physical addresses, passport numbers, dates of birth, health-related details, salary expectations, employment history, and application metadata. If authentic, this type of recruitment dataset is valuable for identity theft and highly tailored phishing, since attackers can use job history and candidate details to craft convincing employment-themed lures.

 

Powered by DarkMirror™

Gaining visibility into deep and dark web threats can be extremely useful from an actionable threat intelligence and digital risk protection perspective. However, monitoring all sources is simply not feasible, which can be time-consuming and challenging. One click-by-mistake can result in malware bot infection. To tackle these challenges, SOCRadar’s DarkMirror™ screen empowers your SOC team to follow up with the latest posts of threat actors and groups filtered by the targeted country or industry.