800 GB Stolen, No Police Called, Data Still on Sale: Inside India’s Most Alarming Hospital Breach
A Kerala hospital’s silence after a catastrophic ransomware attack reveals everything wrong with how institutions respond to cybercrime —…
Cybersecurity Explained
800 GB Stolen, No Police Called, Data Still on Sale: Inside India’s Most Alarming Hospital Breach
A Kerala hospital’s silence after a catastrophic ransomware attack reveals everything wrong with how institutions respond to cybercrime — and what India’s new privacy law is about to change

Imagine walking into a hospital. Nurses at their stations. Patients being admitted. Monitors beeping. Everything looks completely normal.
But somewhere on the dark web, right now, a group of cybercriminals is selling 800 gigabytes of that hospital’s most sensitive records — patient diagnoses, Aadhaar numbers, financial ledgers, board meeting minutes — to the highest bidder. And the hospital? They’ve filed no police complaint. Told no one. Officially, nothing happened.
This is a real incident. A prominent private multi-specialty hospital in Ernakulam, Kerala. The attackers: an international ransomware group called “The Gentlemen”, also tracked by Microsoft as Storm-2697. As of June 2026, they’ve claimed 483 victims across 70+ countries. India is one of their confirmed priority targets.
To understand how this happened, you need to understand the criminal business model behind it.
Crime as a Franchise: What Is Ransomware-as-a-Service?
Think about fast food franchises. McDonald’s doesn’t personally cook every burger in the world. They build the system — the recipes, the equipment, the brand — and license it to individual operators. McDonald’s takes a cut of every transaction.
Ransomware-as-a-Service (RaaS) works exactly the same way, except the product is a cyberattack.
A core criminal group builds the malware, the infrastructure, and the negotiation platform. Then they recruit affiliates — other criminals who use this toolkit to attack real targets. The Gentlemen offer their affiliates a 90% revenue cut — the highest split currently documented in the ransomware market. That’s not generosity. It’s a recruitment weapon designed to attract the most capable attackers away from rival groups.
💡 Think of it like this: the developers are the franchise headquarters. Affiliates are the individual operators. And the “customers” — hospitals, utilities, corporations — never agreed to do business with either.

RaaS Franchise Model
📖 Key Terms Ransomware — Malicious software that encrypts or steals data, then demands payment for its return or suppression. RaaS (Ransomware-as-a-Service) — A criminal model where developers rent ransomware tools to affiliates who execute attacks and share profits. Double Extortion — Attackers both steal data AND encrypt systems, so victims face two separate threats even if backups are intact.
Who Are “The Gentlemen”? Their Origin Is Stranger Than Fiction
Their story begins in July 2025, when their core administrator — operating under aliases including hastalamuerte and zeta88 — defected from a rival ransomware group called Qilin. He publicly accused Qilin of withholding $48,000 USD in unpaid commissions on an underground forum called RAMP. He announced his departure. He started fresh.
Except he hadn’t started fresh at all.
A ransomware sample tied to The Gentlemen had already appeared on VirusTotal five days before the public dispute. The departure was pre-planned. The accusation was a cover story. Threat researchers at Ransom-ISAC further identified an operational alias — “Tinker” — that appears in the leaked communications of both Conti and Black Basta, and again in The Gentlemen’s own leaked data. These aren’t new criminals. They’re veterans who rebranded and built a better machine.
So how active are they really? Their own data leak site shows 483 publicly named victims. But Check Point Research found evidence of over 1,570 compromised organisations on a single one of their C2 servers. The publicly visible number is just the tip of the iceberg.

The Gentlemen — Scale & Timeline
📖 Key Terms Data Leak Site (DLS) — A dark web page where ransomware groups publicly name victims and post stolen data samples to pressure payment. C2 Server (Command-and-Control) — A server controlled by attackers that receives stolen data and issues instructions to malware on compromised systems.
The Weapon That Kills Your Antivirus Before It Can Respond
Most people assume that antivirus software protects them. For everyday threats, it does. But The Gentlemen built a dedicated tool to kill security software silently — before it can react.
They call it GentleKiller. Security researchers at ESET documented at least eight variants of it in June 2026. It uses a technique called BYOVD — Bring Your Own Vulnerable Driver.
Here’s how it works. Windows allows certain deep-level system drivers to interact with hardware. GentleKiller loads a legitimately signed — but deliberately vulnerable — driver, impersonating trusted software like Kaspersky or Valorant. It then exploits a flaw in that driver to gain Ring-0 access: the deepest, most privileged layer of the operating system. From there, it terminates any process it wants — including security tools from CrowdStrike, SentinelOne, Microsoft Defender, and 45 other products.
Think of it like a security guard who checks badges at the entrance. GentleKiller doesn’t forge a badge — it finds a hidden tunnel underneath the guardpost entirely.
But here’s where it gets interesting: defeating GentleKiller requires a Windows feature most organisations haven’t enabled. Standard antivirus tamper-protection operates at a layer above where this attack happens. Only HVCI (Hypervisor-Protected Code Integrity) — which enforces what can run at kernel level — can stop it. Most hospital IT departments have never heard of it.

GentleKiller BYOVD Attack Flow
📖 Key Terms BYOVD (Bring Your Own Vulnerable Driver) — Exploiting a legitimate but vulnerable system driver to gain deep OS access, bypassing security controls. Ring-0 / Kernel Level — The most privileged layer of an OS; code here has unrestricted access to all system resources. HVCI — A Windows feature that prevents unauthorised code from running at kernel level; one of the only effective defences against BYOVD.
How the Kerala Hospital Was Breached: Five Phases, One Email
The Ernakulam attack followed a structured kill chain — a sequence of phases where each step unlocks the next, like a combination lock that must be cracked in order.

Kill Chain — 5-Phase Attack Sequence
Phase 1 — Spear-Phishing: Targeted emails sent to hospital administrative staff. Not a mass blast — a personalised lure. One employee clicked. The attackers now had access to internal mailboxes. Emails from a real, trusted internal account bypass spam filters automatically.
Phase 2 — Privilege Escalation: Using documented exploits like PetitPotam and ZeroLogon, the attackers elevated from a regular user account to domain administrator — the master key to the entire network.
Phase 3 — Lateral Movement + EDR Kill: The attackers mapped the internal network using legitimate admin tools like AnyDesk, blending into normal traffic. Then GentleKiller was deployed, silencing security software at the kernel level before proceeding.
Phase 4 — Exfiltration: AI-assisted scripts identified and siphoned targeted data to C2 servers via SystemBC SOCKS5 tunnels — covert channels hidden inside normal-looking traffic. Data was metered slowly and deliberately to avoid triggering bandwidth alerts. 800 GB left the building undetected.
Phase 5 — Encryption + Extortion: Ransomware was deployed network-wide through weaponised Group Policy Objects (GPOs) — administrative tools normally used by IT departments to push software updates. The ransomware carries a — spread flag enabling automatic worm-propagation. Network disruptions followed. The data was listed for sale.
The entire sequence is like a professional moving crew that enters through a trusted side entrance, photographs everything, slowly loads the most valuable items into a sealed van over several days — then honks the horn once they’re safely down the road.
📖 Key Terms Spear-Phishing — A targeted phishing attack aimed at a specific person, using personalised details to appear legitimate. GPO (Group Policy Object) — A Windows admin tool for deploying settings across a network; weaponised here to push ransomware to every connected machine simultaneously. SystemBC — Proxy malware creating covert tunnels to hide attacker communications and data exfiltration.
The Cover-Up That Made Everything Worse
When hospital leadership discovered the breach, their first move was to check whether backups were intact. They were. So management concluded — incorrectly — that the breach was contained. No large-scale theft, they assumed.
This is a documented cognitive bias in ransomware response: confusing backup integrity with exfiltration scope. The two are completely separate. The attackers had already copied everything out before touching a single backup file.
Rather than notify Kerala Police or CERT-Kerala, the hospital quietly contracted a private international cybersecurity firm to clean the malware and restore operations. No FIR was filed. No regulatory body was notified.
And here’s the part that most people don’t realise: Under India’s CERT-In Cyber Security Directions (IT Act 2000), every organisation must report cybersecurity incidents to CERT-In within six hours of detection. Not six days. Not after remediation. Six hours. That window closed long ago.

India Breach Compliance Timeline
Kerala Police Cyber Dome independently discovered the breach after a 30 MB proof-of-compromise sample surfaced on dark web forums. They verified it. But because the hospital refuses to formally acknowledge the incident, Cyber Dome cannot conduct an aggressive forensic investigation on live servers without either an FIR or a court order. As of June 25, 2026, they have neither.
The data is still on sale. Nobody is stopping it.

The Hacker Gets Hacked
The Plot Twist: The Hackers Got Hacked
In early May 2026, The Gentlemen suffered their own breach.
A hosting provider used by underground actors was compromised, exposing credentials tied to The Gentlemen’s own backend. Within days, their 16.22 GB internal dataset — six months of private Rocket.Chat communications — was released freely on multiple underground forums.
The leak exposed ransom negotiation transcripts, victim rosters, Bitcoin wallet addresses, affiliate recruitment records, and internal tool documentation. Among the revelations: administrator zeta88 built the entire negotiation panel using AI coding tools in three days. The group uses stripped-down open-weight LLMs to automatically analyse hundreds of gigabytes of stolen victim data.
And most critically for anyone assessing the Ernakulam breach: the leaked chats confirm that The Gentlemen weaponised stolen medical records to personally extort individuals even after negotiations had concluded. Paying a ransom does not delete the data. The evidence now says so explicitly.
The group survived the leak. By May 16, they were an official BreachForums partner. Operations continued.
📖 Key Terms Open-Weight LLM — An AI language model whose parameters are publicly available, allowing groups to download and modify it for their own purposes. Proof of Compromise — A sample of stolen data released publicly by attackers to prove the breach is real and apply pressure on victims.
Why It Matters — To You, Right Now
If you’ve ever been a patient at a private hospital in India, your records are sitting in a database somewhere. The question is whether that organisation is prepared for what just happened in Ernakulam.
India’s Digital Personal Data Protection (DPDP) Act is actively closing the gap. The Data Protection Board of India (DPBI) was constituted in November 2025. Full enforcement — including mandatory breach notification and penalties of up to INR 250 crore (approximately USD 30 million) per violation — begins May 2027. The DPDP Rules explicitly require encryption, access controls, audit logging, and ISO 27001 alignment.
For the Ernakulam hospital, the math is becoming uncomfortable. The cost of silence — regulatory penalties, legal exposure, patient trust destroyed — will vastly exceed whatever they saved by avoiding the news cycle.
Silence is never free in cybersecurity. It just delays the invoice.

Stolen Data Vault — 3 Categories
Key Takeaways
- RaaS is a criminal franchise — The Gentlemen offer affiliates a 90% revenue cut, the highest in the market, to recruit top talent.
- GentleKiller defeats 46+ security products at the kernel level using BYOVD; standard antivirus cannot stop it.
- The breach started with one phishing email — the most sophisticated kill chain in the world had a human entry point.
- The hospital’s cover-up is itself a violation — CERT-In mandates a 6-hour reporting window that was ignored.
- Paying a ransom won’t recover the data — The Gentlemen’s own leaked chats confirm data weaponisation continues after payment.
⚠️ Going Deeper
If the basics clicked and you want to go further, here’s what to explore next:
- MITRE ATT&CK — Map every phase of this attack to technique IDs: T1566.001 (Spearphishing), T1078 (Valid Accounts), T1486 (Data Encrypted for Impact). This is how defenders build detection rules.
- BYOVD and HVCI — Read ESET’s June 2026 GentleKiller report for the most detailed technical breakdown of kernel-level EDR evasion currently documented.
- India’s DPDP Act Rules (Nov 2025) — Specifically Rule 6 on security safeguards and breach notification. Compare with GDPR Article 33’s 72-hour window.
- RaaS Affiliate Economics — The Conti leaks (2022) and Black Basta leaks (Feb 2025) reshaped the entire ransomware market. The Gentlemen are a direct product of that disruption.
🧠 Quick Knowledge Check
Try answering these before scrolling to the answer key — you’ll be surprised how much stuck!
- What does “double extortion” mean, and why does it make backups less useful as a defence?
- What revenue split do The Gentlemen offer affiliates, and why is it significant?
- What technique does GentleKiller use, and which layer of the OS does it attack?
- What was the very first phase of the Ernakulam attack?
- Why did hospital management believe the breach was contained when it wasn’t?
- What is India’s mandatory incident reporting window under CERT-In Directions?
- What did the May 2026 internal leak reveal about data deletion guarantees?
- What are GPOs, and how were they weaponised in this attack?
- Name the three categories of data in the stolen 800 GB vault.
- 🔍 Research question: The Gentlemen used SystemBC as a SOCKS5 proxy for exfiltration. What is SOCKS5, how does it differ from HTTP proxies, and why do ransomware groups specifically prefer it for hiding C2 traffic?
📖 Answer Key
No peeking before you’ve tried! Answers are here to confirm, not replace, your thinking.
Q1: Double extortion means attackers steal data first, then encrypt systems. Even if victims restore from backup, the stolen data can still be published or sold — two separate threats from one attack.
Q2: 90% to affiliates, 10% to operators — the highest documented split in the current RaaS market. It’s a recruitment strategy to attract the most capable attackers away from competing groups.
Q3: BYOVD (Bring Your Own Vulnerable Driver) — loading a legitimately signed but exploitable driver to gain Ring-0 (kernel-level) access, from which security software processes are silently terminated.
Q4: A targeted spear-phishing campaign against administrative staff, resulting in the hijacking of internal corporate mailboxes.
Q5: The offline backup arrays were unaffected. Management confused backup integrity with exfiltration scope — a documented cognitive bias in ransomware response.
Q6: Six hours from detection. This is a hard legal requirement under the CERT-In Cyber Security Directions issued under the IT Act 2000.
Q7: The leaked Rocket.Chat communications confirmed The Gentlemen weaponised stolen medical records for personal extortion even after ransom negotiations concluded. No data deletion guarantee from this group is credible.
Q8: Group Policy Objects are Windows administrative tools normally used to push software updates across a network. The attackers deployed ransomware through weaponised GPOs, pushing the payload to every connected machine simultaneously.
Q9: PHI (clinical records, treatment histories, lab results), PII (Aadhaar/PAN, addresses, phone numbers), and Institutional Data (unencrypted financial ledgers, admin systems, board minutes).
Q10: SOCKS5 is a general-purpose proxy protocol that routes TCP/UDP traffic without inspecting packet contents, unlike HTTP proxies which only handle web traffic and reveal more metadata. Ransomware groups prefer SOCKS5 because it’s application-agnostic, harder to fingerprint, and blends into legitimate network traffic patterns — making C2 communications and exfiltration tunnels significantly harder for network monitoring tools to flag.
The hospital’s servers have been cleaned. The malware is gone. Operations resumed. On paper, the crisis is over.
But 800 gigabytes of patient records are still listed for sale today. The group that took them has 483 victims and counting. And the only thing preventing investigators from accessing the hospital’s servers is a formal complaint that nobody wants to sign.
In cybersecurity, silence is never neutral. It’s a choice — and someone else always pays the price for it.
If you found this useful, give it a clap 👏 — it helps more people discover it. And if you have questions, drop them in the comments. I read every one.
Want to talk cybersecurity, share resources, or just connect? Find me on LinkedIn — I’m always happy to connect with curious minds.
메타데이터
- post_id
- 0a6ceab32b60
- slug
- 800-gb-stolen-no-police-called-data-still-on-sale-inside-indias-most-alarming-hospital-breach-0a6ceab32b60
- url
- https://systemweakness.com/800-gb-stolen-no-police-called-data-still-on-sale-inside-indias-most-alarming-hospital-breach-0a6ceab32b60
- canonical_url
- https://systemweakness.com/800-gb-stolen-no-police-called-data-still-on-sale-inside-indias-most-alarming-hospital-breach-0a6ceab32b60
- author_url
- https://medium.com/@jijoshibuwork
- status
- ok
- fetched_at
- 2026-07-11 16:48:19