惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Recent Announcements
Recent Announcements
人人都是产品经理
人人都是产品经理
月光博客
月光博客
博客园 - 三生石上(FineUI控件)
GbyAI
GbyAI
博客园 - 司徒正美
美团技术团队
Vercel News
Vercel News
IT之家
IT之家
U
Unit 42
Y
Y Combinator Blog
罗磊的独立博客
Microsoft Security Blog
Microsoft Security Blog
MongoDB | Blog
MongoDB | Blog
Jina AI
Jina AI
V
Visual Studio Blog
B
Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
MyScale Blog
MyScale Blog
博客园 - 叶小钗
A
About on SuperTechFans
WordPress大学
WordPress大学
Hugging Face - Blog
Hugging Face - Blog
B
Blog RSS Feed

Enterprise – Silicon Republic

Recovery readiness a missing link in cyber resilience, finds report EU finally gets its hands on Anthropic’s Mythos New Irish dispute body to tackle illegal online content launched Rhysida leaks 5.7TB of sensitive Berlin state data in major hack ‘Keeping OT security up to date is more than patching systems’ HSE fined €645,000 for storing records in decrepit conditions Boston Scientific cyberattack: Cork staff asked to work remotely Report: Only sectors aiding AI adoption sure to grow from it Why connectivity and cybersecurity can't be treated separately French authorities investigating hack of national tax authority Why employee retention is at the heart of the cyber skills gap Levi Strauss corporate data stolen in cyberattack Levi Strauss corporate data stolen in cyberattack How might a system ‘leak secrets’ without being hacked? What is a side-channel attack in cybersecurity? OpenAI agents breach Modal client system after Hugging Face hack OpenAI agents breach Modal client system after Hugging Face hack Report: EMEA businesses not reaping benefits from their AI spend Report: EMEA businesses not reaping benefits from their AI spend Transport for London hackers jailed for five and a half years Transport for London hackers jailed for five and a half years Commission refers Ireland to CJEU for failing to enact cyber rules Commission refers Ireland to CJEU for failing to enact cyber rules Cloudflare to block AI crawlers from ad-supported webpages by default Cloudflare to block AI crawlers from ad-supported webpages by default Google ordered to pay Klarna nearly $2bn in abuse-of-power row Google ordered to pay Klarna nearly $2bn in abuse-of-power row Upcoming iPhone 18 model leaked in Tata Electronics hack New iPhone 18 models reportedly leaked in Tata Electronics hack Data breaches going unreported – Irish compliance survey
New XP95 hacker group targets Dublin recruitment platform...
2026-04-13 · via Enterprise – Silicon Republic

Over the weekend, Northern Irish health trusts were on high alert after the XP95 hacker group claimed to have accessed hundreds of thousands of files.

A recruitment platform used by Northern Ireland’s health trusts has reportedly suffered a cyberattack from the relatively new hacker group XP95, which is claiming to have accessed hundreds of thousands of files.

With headquarters in Dublin and offices in Belfast, Toronto and Melbourne,  BBC NI reported over the weekend that it has seen an email from Healthdaq’s data protection officer, saying it had become aware of unauthorised access to data held on its platform on 30 March, and that the issue had been contained.

“The incident has been identified as a confidentiality breach involving unauthorised access and extraction of data,” BBC NI quoted the email, which said that names, contact details, CVs, forms of government ID and in some cases even health data could be among the data that was stolen.

The cited email went on to warn that the nature of the data stolen meant that there was a risk of misuse, from identity theft to fraud. According to the BBC, the health trusts have warned all staff to be aware of a potential cyber incident and to be extra vigilant.

Healthdaq confirmed to SiliconRepublic.com that “Healthdaq has been the victim of a cybersecurity incident”.

“The incident has been reported to the relevant regulatory and law enforcement authorities including the Garda National Cyber Crime Bureau,” it said, adding that because the incident is the subject of an active criminal investigation, it could not make any further comments at this time.

According to threat intelligence firm Red Piranha, the XP95 ransom actor was first observed on March 4, and its first known attack was on Eholo Health, a Spanish mental health SaaS platform serving more than 10,000 psychologists across Spain and Andorra.

“The actor’s BreachForums profile was freshly created at the time of first appearance, with no prior references in threat intelligence reporting linking XP95 to any known organised group or prior campaigns,” said Red Piranha in a threat intelligence report from early March.

“Unlike conventional ransomware operators, XP95 does not deploy encryption malware,” it said. “The group operates a pure exfiltration-and-extortion model: sensitive data is stolen from the victim environment, a proof-of-compromise sample is published on a Tor-hosted data leak site (DLS) and cross-posted to BreachForums, and a ransom demand is issued with a hard payment deadline.”

Should the ransom not be paid, XP95 then threaten to publicly release the stolen dataset or put it up for sale. Reporting suggests that Healthdaq has indeed received a ransom request.

Updated 1.50pm 14 April 2026: The story has been updated to incorporate a comment from Healthdaq. 

Don’t miss out on the knowledge you need to succeed. Sign up for the Daily Brief, Silicon Republic’s digest of need-to-know sci-tech news.