HFMA Allegedly Breached as Threat Actor Claims Sale of 200K Records

A threat actor claims to be selling 200,000 HFMA records after an alleged failed extortion attempt, though the breach remains unverified.
Screenshot of a cybercrime forum post in which a threat actor claims to be selling a database allegedly stolen from the Healthcare Financial Management Association (HFMA). The post claims more than 200,000 records were compromised and includes redacted samples described as sponsor contact lists and board member email directories.
Redacted screenshot of a forum post in which a threat actor claims to be selling data allegedly stolen from the Healthcare Financial Management Association (HFMA), including purported sponsor records, organizational contacts, and internal documents. BreachNews has not independently verified the claims or the authenticity of the alleged dataset.

A threat actor claims to have breached the Healthcare Financial Management Association (HFMA), alleging the theft of more than 200,000 records and internal organizational documents following an alleged failed extortion attempt.

The claim was posted on a cybercrime forum on June 9, 2026. According to the actor, HFMA was given 2 weeks to respond to a ransom demand before the data was offered for sale.

BreachNews has not independently verified the claims or confirmed that any unauthorized access occurred within HFMA systems.

Sample includes sponsor and leadership contacts

The actor claims to possess more than 200,000 records along with PDF and XLSX files allegedly obtained from HFMA systems. The purported dataset is being advertised for sale for $1,500.

Samples published alongside the claim appear to contain business contact information associated with HFMA sponsors, board members, chapter leadership, and administrative personnel.

The records reviewed by BreachNews include names, professional email addresses, company affiliations, leadership positions, sponsorship information, and organizational contacts connected to healthcare finance organizations and industry partners.

Organizations appearing within the sample include Bank of America, PwC, Deloitte, KPMG, Change Healthcare, Latham & Watkins, and other companies that maintain relationships with HFMA through sponsorship and industry participation programs.

Scope of alleged breach remains unverified

While the sample appears relevant to HFMA operations, it does not independently verify the actor’s broader claims regarding more than 200,000 records or complete access to organizational systems.

The actor’s forum account appears to have limited posting history and no publicly established track record of prior breach disclosures. New accounts occasionally emerge with legitimate data, but cybercrime forums also frequently attract actors seeking to exaggerate or misrepresent datasets in order to generate sales.

The published sample primarily consists of professional contact information rather than patient records, healthcare information, insurance data, or financial account information. No evidence has been presented publicly showing exposure of medical records or other sensitive healthcare data.

HFMA had not issued any public statement regarding the allegations at time of publication.

Additional healthcare sector coverage:

Picture of m00s3c

m00s3c

Moose (@m00s3c) is the author of BreachNews, focusing on data breach intelligence, dark web monitoring, and threat analysis. His work involves analyzing breach claims, reviewing leaked datasets, and tracking threat actor activity to provide clear, factual reporting.

Latest News

BREACHNEWS.COM/SUPPORT/

Support Independent News.

Help support breach monitoring, investigations, infrastructure, and reporting.

Support the site
INTEL.BREACHNEWS.COM

Live Cyber
Threat Map

Explore live cyber activity, recent breach reports, KEV alerts, and public threat feeds from a single interactive dashboard.

Launch Threat Map