A threat actor is claiming to have stolen approximately 1.16 million patient records allegedly linked to Transtreme and is threatening to sell the data unless the company pays a ransom.
The forum post, published on July 26, alleges the dataset includes information associated with HealthNet-CMC Medicare members and Aetna-CA members. At the time of publication, neither Transtreme nor the referenced organizations had issued any public statement regarding the claims, and no independent confirmation of the alleged breach has been established.
Ransom demand accompanies breach claim
According to the post, the actor is demanding payment from Transtreme and warns that the alleged dataset will be sold if negotiations do not take place.
The actor claims the data includes approximately:
- 97,000 HealthNet-CMC Medicare member records
- 171,000 Aetna-CA member records
- 734 medical business account records
- Employee information
Combined, the actor alleges the breach contains approximately 1.16 million unique patient records, although that figure has not been independently verified.
Claimed data includes Medicare and insurance information
According to the listing, the alleged dataset contains personally identifiable information and healthcare-related records, including names, dates of birth, home addresses, phone numbers, insurance policy numbers, customer member IDs, physician information, and Medicare Beneficiary Identifiers (MBIs).
The actor also claims the records include provider identifiers, visit information, effective dates, and business account data related to healthcare organizations. BreachNews is intentionally not reproducing the sample records published by the actor because they contain sensitive personal information.
Large healthcare datasets remain attractive targets
If authentic, the alleged dataset could present a significant risk of identity theft, insurance fraud, targeted phishing, and other forms of social engineering. Healthcare records are frequently among the most valuable forms of stolen data because they combine personal identifiers with insurance and medical information that cannot easily be changed.
The actor further claims the data has been validated and is offering multiple purchase options for portions of the alleged dataset. Those assertions remain unverified.
No public confirmation
At the time of publication, no public statements regarding the alleged incident had been identified from Transtreme, HealthNet-CMC, or Aetna. It is therefore not possible to independently determine whether the claimed breach occurred or whether the data being advertised is authentic.
The incident follows several recent breach claims posted by different threat actors targeting organizations across multiple sectors. As with all unverified forum claims, the allegations should be treated cautiously until corroborating evidence becomes available.











