leak
Potential
Morocco (MA)
healthcare
Sothema: alleged internal document leak (second post)
Sothema (Morocco)
CompanySothema (Morocco)
CountryMorocco (MA)
Sectorhealthcare
Breach date2025-06-27
People affected100,000
Data typesNot disclosed
<p>On 27 June 2025, darkMods claims to have obtained access to data belonging to <strong>Sothema (Morocco)</strong>, Morocco on a hacking forum. The claimed data includes internal documents, banking files, salary records. A limited sample was published to support the claim.</p>
<h2>What the source reveals</h2>
<p>We have received credible information indicating the existence of a set of internal documents related to SOTHEMA, including: Forged documents Sensitive banking files Confidential salary records These materials suggest the presence of financial and administrative manipulation potentially involving certain employees and company officials. ๐งพ Names mentioned in the documents: Lamia Tazi (Company Executive) Mehdi Berrada (Company Director) Additional names have not yet been disclosed. ๐ Contents of the leak include: Allegedly forged payroll and financial reports Names of employees implicated in unl</p>
<h2>Risks</h2>
<ul>
<li>Financial fraud using compromised payment records, bank details, or transaction histories</li>
<li>Medical identity theft and insurance fraud using patient records, treatment histories, and diagnoses</li>
<li>Violation of patient privacy regulations, potentially triggering mandatory reporting to health authorities</li>
<li>Patient safety risks if treatment or medication records were altered or deleted</li>
<li>Reputational damage and erosion of customer, citizen, or stakeholder trust in the affected organisation</li>
<li>Legal liability and regulatory fines under applicable data protection frameworks</li>
</ul>
<h2>What remains unknown</h2>
<ul>
<li>the total volume of data compromised and whether it includes additional categories beyond those disclosed</li>
<li>the method by which the data was obtained - whether through a direct database compromise, an insecure API, or a third-party breach</li>
<li>whether the data has been sold or distributed to additional parties beyond the forum post</li>
</ul>
<h2>Conclusion</h2>
<p>While the claim has not been independently verified, the potential exposure of data from Sothema (Morocco) warrants attention. Healthcare data breaches carry particular weight because medical records cannot be changed like passwords. Affected patients should monitor their health insurance statements for fraudulent claims.</p>