The Health Trust Suffers 408GB Data Breach Linked to Qilin
A San Jose-based nonprofit foundation faces a significant data leak attributed to the Qilin ransomware group.
The Health Trust, a nonprofit operating foundation based in San Jose, California, has fallen victim to a substantial data breach. The incident has exposed a massive volume of internal data, raising immediate concerns over the security of the organization's digital infrastructure.
According to data from Breachsense, the breach was discovered on June 6, 2025. The incident is attributed to the threat actor known as Qilin, a sophisticated ransomware group. The scale of the leak is significant, with approximately 408GB of data reported as compromised and leaked.
The Threat Landscape
This attack occurs amidst a broader trend of targeting healthcare-adjacent organizations and nonprofits. Qilin is known for employing double-extortion tactics, where data is not only encrypted but also exfiltrated to be leaked publicly if ransom demands are not met. By targeting foundations and health-related entities, threat actors exploit the critical nature of the services provided to exert maximum pressure on the victim.
Industry Implications
Breaches involving health-related organizations are particularly critical due to the sensitivity of the information typically handled. While the specific types of data within the 408GB leak have not been detailed, the potential exposure of Protected Health Information (PHI) carries severe regulatory implications. Under laws such as the Health Insurance Portability and Accountability Act (HIPAA), organizations are mandated to maintain strict safeguards for patient data, and failures can lead to heavy fines and mandatory federal audits.
Next Steps
It remains to be confirmed exactly what categories of personal or health information were contained in the 408GB leak. Observers are now waiting for official statements from The Health Trust regarding the nature of the compromised files and whether affected individuals have been notified. The industry will be watching to see if this breach reveals further vulnerabilities in the cybersecurity posture of nonprofit health foundations.