Advanta Genetics LLC
About the organisation
[health] Advanta Genetics LLC β a respected CLIA/CAP-accredited clinical toxicology and molecular diagnostics laborator. The exposed material includes: Tens of thousands of real patient lives β including highly sensitive chronic opioid therapy charts flagged by the Texas Medical Board and elderly Medicare audit records. Provider identities and prescribing power β SSNs, DEA numbers, and state licenses from 20+ states that can be turned into black-market "script pads". Gold-standard identity theft kits β W-2s, I-9s with passport scans, and full employee packages for 50+ staff. 102 complete QuickBooks company files exposing every vendor, payroll run, bank link, and financial secret across the Advanta/RedLeaf/OSPRI empire. High-value trade secrets β OSPRI Biopath investment decks, valuation models, FDA pre-submission packets, and the proprietary "The Brain" AI diagnostic architecture. Explosive privileged attorney-client memos on active regulatory battles (Texas Medical Board Remedial Plan #19-153 and a federal NORA subpoena). Active Directory domain controller data (NTDS.dit and SAM hives).
What the listing means
Advanta Genetics LLC appeared on the aurora leak site on 29 April 2026. Groups publish a victim once negotiations stall or as pressure during them, so a listing usually means data was already exfiltrated β the attack itself is dated 17 April 2026, 12 days before the listing. This group has published 1 claim in the last 30 days and remains active.
Recommended actions
- Treat any unsolicited message referencing Advanta Genetics LLC as suspicious β leaked data gets weaponised for phishing within days.
- If you hold an account on aalabs.com, change that password now, update it anywhere you reused it, and enable two-factor authentication.
- Other Healthcare organisations should review this group's known TTPs and validate detection coverage against them.
- Watch for follow-on extortion: stolen data is often re-leaked or resold after the initial listing.
- A leak-site listing is a claim made by the attacker, not a confirmed breach β check the organisation's own disclosures before acting on it.
Leak-site evidence
Listing URL https://www.ransomware.live/id/QWR2YW50YSBHZW5ldGljcyBMTENAYXVyb3Jh
Show leak-site screenshot
Captured from the group's extortion site. It may contain the victim's data or the attacker's messaging.