On October 28, 2025, the Malaysian healthcare provider hicc.com.my appeared on the leak site of the ransomware group Devman. The attackers claim to have stolen 60 GB of internal files and are demanding a $500,000 ransom.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch h*i**c*.c*m.my
Get alerted the next time h*i**c*.c*m.my files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about h*i**c*.c*m.my’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Available reporting describes the incident as a ransomware attack in which Devman exfiltrated internal documents before encrypting systems. The group published a sample of the stolen data on its onion site, listing the victim as hicc.com.my. No confirmed total number of affected individuals has been released, but healthcare providers routinely hold sensitive patient records, employee payroll files, insurance details, and internal correspondence. The ransom demand stands at $500,000, with the data volume listed as 60 GB.
Why This Matters for You and Your Family
When a healthcare organization loses control of internal files, the information inside often includes names, addresses, dates of birth, national identification numbers, medical histories, and sometimes banking details for direct-debit payments. If your family has ever used this provider, any of those records could now sit in an attacker’s archive. Once that data reaches underground markets, it becomes raw material for identity theft, insurance fraud, or targeted scams against you or your children. The breach also signals that even mid-sized regional clinics remain attractive targets, meaning families must assume their own records could surface without warning.
The Doxxing and Identity-Chain Implications
Stolen internal files frequently contain spreadsheets that link patient names to email addresses, phone numbers, next-of-kin contacts, and sometimes employee login credentials. Attackers chain these fragments together: an email from one record matches a reused password from another breach, a phone number ties to a child’s gaming account, and suddenly a single leak becomes a complete profile. Public reporting indicates that credential leaks like this one routinely cascade into account takeovers across email, banking, and gaming platforms. Children’s gaming accounts are especially vulnerable because parents often reuse the same passwords or security questions drawn from family medical or address records.