Proliance Surgeons Data Breach

Alleged

Ransomware claim involving Proliance Surgeons

Published: Sep 2, 2026 payoutsking
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Proliance Surgeons
Industry
Healthcare
Threat Actor
payoutsking
Date of Incident
Sep 2, 2026

Executive Summary

Proliance Surgeons, a healthcare provider operating across multiple clinical locations in the Pacific Northwest, has been listed as a victim by the Payoutsking ransomware group. The listing appeared on Payoutsking’s dark web portal on September 2, 2026, and was identified through SOCRadar’s Dark Web Monitoring service. While the listing is claimed, it is not yet independently confirmed as a confirmed breach. The nature of Proliance Surgeons’ operations in the healthcare sector, dealing with sensitive patient data and critical infrastructure, makes it a potentially attractive target for ransomware and extortion activities. The Payoutsking ransomware group has demonstrated a focused operational strategy, claiming seven victims in the 60 days prior to this listing. Their targeting has predominantly affected entities in the United States and Italy, with a notable inclination towards the Healthcare and Professional Services sectors. Recent victims include Welldyne (United States, Healthcare), H.W. Lochner (United States, Professional Services), and Casta Diva Group (Italy, Hospitality). Proliance Surgeons represents Payoutsking’s second claimed US healthcare target within this recent period, indicating a discernible pattern rather than isolated incidents.

Technical Analysis

SOCRadar’s stealer-log query against proliancesurgeons[.]com revealed a significant exposure of credentials. The analysis uncovered 11 employee credentials originating from organization-controlled systems (Category A). These included access to the federated identity provider at adfs.proliancesurgeons[.]com, an internal clinical portal at voaphoenix.proliancesurgeons[.]com/phxportal, and an internal organizational portal at my.proliancesurgeons[.]com. Additionally, three records indicated the presence of customers or third-party users on organization systems (Category B), and a further nine records showed corporate users accessing external services (Category C). This multifaceted exposure suggests potential workstation compromise alongside direct access to identity infrastructure. The identified credentials show a freshness window between February 20 and August 19, 2026, spanning a total of six months. Crucially, ADFS credentials associated with the same employee were observed across multiple dates within this period without any indication of rotation. This suggests that these credentials remained valid and accessible throughout the entire exposure window, rather than being compromised at a single point in time. The lack of rotation for these credentials is a critical finding, as it implies a persistent vulnerability. The exposure of ADFS credentials for a prolonged period, coupled with the fact that Proliance Surgeons has been listed by a ransomware actor known to target the healthcare sector, presents a high-severity security finding. While these specific credentials have not been definitively confirmed as Payoutsking’s entry point, the circumstantial evidence of their extended availability and the group’s targeting patterns create a strong alignment. Infostealer logs feeding into ransomware operations is a well-documented threat actor tactic. Immediate priorities for Proliance Surgeons should include a thorough audit of their ADFS and broader identity infrastructure. This should be accompanied by the rotation of all credentials found within the identified sample and a forensic review of access logs for the clinical portal throughout the February to August 2026 period.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.