ransomware
Potential
Tunisia (TN)
healthcare
Societe Tunisienne de Radiologie listed by the Nova ransomware group
Societe Tunisienne de Radiologie (STR)
CompanySociete Tunisienne de Radiologie (STR)
CountryTunisia (TN)
Sectorhealthcare
Breach date2025-12-15
People affected100,000
Ransomware groupnova
Data typesNot disclosed
<p>On 15 December 2025, the <strong>nova</strong> ransomware group listed <strong>Societe Tunisienne de Radiologie (STR)</strong> on its dedicated leak site in Tunisia. The group claims to have exfiltrated data from the organisation, a healthcare organisation, before publishing the victim on its leak site.</p>
<h2>What the source reveals</h2>
<p>The Tunisian Society of Radiology (STR)
was created in 1952 by the late Doctor Ali Fourati under the name of the Tunisian Association of Electro-Radiology.</p>
<h2>Risks</h2>
<ul>
<li>Exposure of patient medical records, treatment histories, and personal health information</li>
<li>Violation of health data protection regulations, potentially triggering mandatory breach notification requirements</li>
<li>Disruption to healthcare service delivery if clinical or appointment systems were encrypted</li>
<li>Medical identity theft using stolen patient records for fraudulent insurance claims</li>
<li>Permanent loss of data integrity if backups were also compromised or encrypted</li>
<li>Regulatory and legal consequences depending on data protection laws in the affected jurisdictions</li>
</ul>
<h2>What remains unknown</h2>
<ul>
<li>the volume and specific data types exfiltrated from the organisation</li>
<li>the date of the initial intrusion and the attack vector used</li>
<li>whether the organisation engaged with the attackers or paid any ransom demand</li>
</ul>
<h2>Conclusion</h2>
<p>Ransomware attacks on healthcare organisations risk both patient privacy violations and disruption to critical medical services. The affected organisation should conduct a thorough forensic investigation, notify relevant regulatory authorities, and communicate transparently with affected stakeholders. Organisations in Tunisia should review their ransomware preparedness, including offline backup verification and incident response testing.</p>