Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
healthcare-sector-threatbreach-disclosure-notificationthird-party-vendor-breachransomware-group-operation

XP95 Data-Theft Attack on Healthdaq Exposes Sensitive Healthcare Recruitment Records

Updated 1mo agoFirst seen May 7, 20264 sources

Healthdaq, a Dublin-based recruitment platform used by Northern Ireland health trusts and other public health bodies, disclosed unauthorized access to its systems after attackers linked to the XP95 extortion group claimed to have stolen nearly half a million files. Reported exposed data includes names, contact details, CVs, qualifications, passport copies, other government-issued identification, criminal background checks, vaccine records, forms, and in some cases health information. Healthdaq said it detected the breach on 30 March, contained the incident, and notified regulators and law enforcement, including the Garda National Cyber Crime Bureau, while the UK Information Commissioner's Office said it is assessing the company’s report.

The incident prompted heightened alerts across Northern Ireland health trusts because of the volume and sensitivity of the compromised records and the risk of identity theft, fraud, and misuse of personal information. Reporting indicates Healthdaq received a ransom demand, and threat intelligence describes XP95 as a newly observed actor using a pure data theft and extortion model rather than file-encrypting ransomware; its first publicly identified victim was Eholo Health, a Spanish mental health SaaS provider serving psychologists in Spain and Andorra. The breach also underscored broader pressure on healthcare technology suppliers after a separate attack on Dutch EPD vendor ChipSoft disrupted hospital services and triggered parliamentary scrutiny over sector dependence on a small number of critical vendors.

Share:
XP95 Data-Theft Attack on Healthdaq Exposes Sensitive Healthcare Recruitment Records
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

7 events from the most recent confirmed update back to the earliest known activity.

7 EVENTS
Apr 14, 20262mo ago

Dutch parliament opens probe into ChipSoft attack

Lawmakers from D66 asked Health Minister Hermans to explain the impact of the ChipSoft incident on healthcare continuity, whether patient data was stolen, and whether cybersecurity requirements for critical healthcare IT suppliers are adequate. The attack also prompted at least 23 data leak notifications to the Dutch Data Protection Authority.

ChipSoft ransomware attack disrupts Dutch healthcare operations

A ransomware attack on ChipSoft, a major Dutch electronic patient dossier software provider, disrupted healthcare operations and led several hospitals to take patient portals offline. ChipSoft reportedly disconnected multiple platforms and began restoring services using new keys.

Apr 13, 20262mo ago

Northern Ireland health trusts placed on high alert over Healthdaq incident

Following reporting on the Healthdaq breach and XP95's claims, Northern Ireland health trusts were placed on high alert because the recruitment platform was used by the trusts. The incident raised concerns over identity theft, fraud, and exposure of sensitive applicant data.

Apr 10, 20263mo ago

ICO confirms receipt of Healthdaq breach report

The UK Information Commissioner's Office said it had received a report from Healthdaq Limited and was assessing the information provided. This confirmed regulatory notification following the breach disclosure.

XP95 claims Healthdaq breach and demands ransom

XP95 claimed responsibility for the Healthdaq intrusion, saying it stole nearly half a million files. Reported exposed data included names, contact details, CVs, qualifications, passport and other government ID copies, criminal background checks, vaccine records, and in some cases health information.

Mar 30, 20263mo ago

Healthdaq detects unauthorized access and contains the breach

Healthdaq said it became aware of unauthorized access to its systems on 2026-03-30 and took steps to contain the incident. The company later reported the matter to regulators and law enforcement, including the Garda National Cyber Crime Bureau.

Mar 4, 20264mo ago

XP95 extortion group is first observed targeting Eholo Health

Threat intelligence reporting says XP95, a data-theft-and-extortion actor, was first observed on 2026-03-04. Its first known victim was Eholo Health, a Spanish mental health SaaS platform serving psychologists in Spain and Andorra.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

8 LINKEDOpen in app
Threat actors
1 linked
Organizations
7 linked
LinkedinMeta PlatformsRedditChipSoftRed PiranhaEholo HealthHealthdaq
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.