Ransomware Group Wallstreet Claims Attack on St. Francis Healthcare Systems of Hawaii
A criminal ransomware group has listed a century-old Catholic nonprofit hospital network on its dark-web claims site. The organisation has not confirmed any incident, and the claim remains unverified.

Key points
- The Wallstreet ransomware group listed St. Francis Healthcare Systems of Hawaii on its dark-web claims page on 3 October 2026, according to monitoring service Ransomware.live.
- Healthcare is the most frequently targeted sector in Wallstreet's claimed victim list.
- St. Francis Healthcare Systems of Hawaii has not publicly confirmed any incident, and the claim could not be independently verified at the time of publication.
- Ransomware listings are sometimes exaggerated or false and are designed to pressure organisations into paying.
St. Francis Healthcare Systems of Hawaii, a Catholic nonprofit hospital network that the group's own post describes as having served Hawaii families since 1927, was listed on the dark-web claims site of a ransomware group called Wallstreet on 3 October 2026. Ransomware is malicious software that locks an organisation's files and systems until a ransom is paid. Leak sites are dark-web pages where ransomware criminals publicly name their alleged victims to shame them into paying before threatening to release stolen data.
No public statement from St. Francis Healthcare Systems of Hawaii confirms that any attack took place. The listing is an unverified criminal claim.
How active is the Wallstreet group?
Active enough to notice. Healthcare appears most often across the sectors where the group has listed victims. That pattern matters: groups that concentrate on healthcare are targeting networks that are typically stretched thin on IT staff and slow to patch, exactly the conditions that make them attractive. In practice, volume like this often means the group is buying initial access from brokers rather than doing all the breaking-in themselves.
We've tracked healthcare incidents closely. Our coverage of the Kairos group's claim against a Vermont school district on 2 October shows the same pattern: a listing appears, the organisation stays silent, and patients or families are left waiting for confirmation that may not come quickly.
Should you worry?
Because no breach has been confirmed, there's no established list of what data, if any, was affected. That uncertainty is precisely when opportunists move.
Anyone who has visited a St. Francis facility or interacted with its systems should watch for phishing: fake emails or text messages that use the hospital's name to trick people into handing over passwords or personal details. Scam callers sometimes pose as breach-notification services and offer "compensation" in exchange for banking details. Hang up.
Don't reuse passwords across accounts, particularly if a St. Francis patient portal or staff login shares a password with personal email or banking. If the organisation sends an official notification, follow its guidance and treat any other message claiming to represent the hospital about this incident with serious suspicion.
| Metric | Figure |
|---|---|
| Sectors represented in Wallstreet's claimed victims | 10 |
| Most targeted sector | Healthcare |
| Date of St. Francis listing | 3 Oct 2026 |
If this ever becomes a confirmed incident, the post-mortem will note that the listing appeared before any public statement. That's not unusual: groups like Wallstreet count on the silence. Watch your inbox this week.



