ransomware Credible Egypt (EG) healthcare

ADG Healthcare: Ransomware Data Leak

ADG Healthcare

📅 21 May 2026
CompanyADG Healthcare
CountryEgypt (EG)
Sectorhealthcare
Breach date2026-05-21
People affected100,000
Ransomware groupOrova
Data typesNot disclosed

Overview

On May 21, 2026, the Orova ransomware group added ADG Healthcare to its public leak site. ADG Healthcare operates in the medical specialists industry and is headquartered in Cairo, Egypt. The company employs roughly 250 to 499 people and reports annual revenue in the 10 to 25 million range. The listing confirms that the group claims to have gained access to the company's systems and to hold data from the organisation.

What was published

The leak site entry for ADG Healthcare includes a victim profile with the company details above. The group did not disclose the volume of data stolen or the categories of records in the listing text. According to the post, the company was attacked on May 21, 2026, and the group presents the incident as an active compromise. No download links or sample files were described in the visible listing content.

Risks for affected individuals

  • Employees of ADG Healthcare may be exposed if personal or professional records were part of the exfiltration.
  • Clients of the medical specialists firm could face phishing attempts if contact details were taken.
  • Corporate information such as contracts, billing data or internal documents could be used for fraud or further targeting.
  • The public nature of the leak site increases the chance that any published data spreads beyond the original post.

What remains unknown

  • The exact number of records or individuals affected has not been disclosed.
  • The categories of data exfiltrated are not listed in the post.
  • It is not known whether the group has released samples, started negotiations, or published the full dataset.
  • The current status of the incident at the company is not confirmed.

What affected people should do

Employees and clients of ADG Healthcare should watch for official communications from the company regarding the incident. Anyone who receives unsolicited messages referencing the company should verify the sender before responding. Individuals should also monitor accounts for unusual activity and consider changing passwords if they reuse credentials across services. The company has not yet made a public statement about the attack, so the details above reflect the claims of the ransomware group.