Listen to this Post

On December 1, 2025, Abdulhadi Hospital in Yemen reportedly became the latest victim of a ransomware attack. According to cybersecurity reports, the threat actor identified as “Devman” allegedly demanded a $350,000 ransom in exchange for 246GB of stolen data. The attack was first brought to light via social media posts, drawing immediate attention from cybersecurity observers and regional authorities. This incident raises serious concerns about the vulnerability of healthcare infrastructure in conflict-affected regions and the growing sophistication of ransomware operations targeting sensitive medical data.
the Incident
The ransomware attack at Abdulhadi Hospital appears to have been executed by the threat group Devman. Early reports indicate that the attackers exfiltrated a massive 246GB of sensitive hospital data, which could include patient records, administrative files, and operational documents. The ransom demand stands at $350,000, payable through online channels, though details of payment methods remain unspecified.
The breach was publicly disclosed through a series of social media posts, including tweets from cybersecurity-focused accounts. The first discovery of the incident was reported on December 1, 2025, but details on when the attack began are unclear. The attackers’ communications reportedly referenced a website, http://ecaretest.com
, as part of their ransom negotiation process.
Cybersecurity analysts have raised alarms over the potential consequences for patient care and privacy. In conflict zones like Yemen, hospitals often operate with limited IT infrastructure, making them particularly susceptible to ransomware. The attack highlights not only the immediate financial risk posed to healthcare institutions but also the long-term operational disruption and potential exposure of sensitive patient information.
Devman, the alleged threat actor, has a history of ransomware activity in the Middle East. The group’s tactics often involve encrypting systems while exfiltrating data to leverage higher ransom payments. There is concern that the stolen information could be sold on underground markets if the ransom is not paid, increasing the risk of identity theft, blackmail, or other cybercrimes.
Social media monitoring shows heightened discussion around this breach, with cybersecurity communities in Yemen, Jordan, and beyond closely tracking the developments. The incident has also triggered discussions on the preparedness of hospitals to handle sophisticated cyberattacks, especially in regions already under strain from political instability and economic hardship.
What Undercode Say:
The Abdulhadi Hospital ransomware attack underscores several critical trends in contemporary cyber threats. First, it illustrates the persistent targeting of healthcare infrastructure, particularly in geopolitically unstable regions where cyber defenses are often underfunded or outdated. Attackers like Devman exploit this vulnerability, knowing that hospitals are more likely to comply with ransom demands due to the life-critical nature of their services.
The demand for $350,000, while significant, is consistent with the operational model of mid-tier ransomware groups who balance ransom size with the probability of payment. Exfiltrating 246GB of data further enhances the leverage of attackers, as they can threaten to release sensitive patient data publicly if payment is not made. This “double extortion” tactic has become a hallmark of modern ransomware campaigns.
From an operational perspective, hospitals in Yemen likely face compounded risks due to limited IT staff, outdated systems, and a lack of robust backup solutions. These factors make it difficult to restore operations quickly without capitulating to ransom demands. International cybersecurity bodies may consider this case a warning to extend support and best practice frameworks to healthcare organizations in conflict zones.
The attack also reflects the growing role of social media in ransomware negotiation dynamics. Publicly visible communications can amplify pressure on organizations to comply while simultaneously alerting the global cybersecurity community. The visibility of the breach online may help authorities track threat actors like Devman but also increases reputational and operational stakes for the hospital.
Technically, the exfiltration of 246GB suggests that attackers had access to network drives, possibly including medical imaging databases, patient management systems, and administrative records. This level of access indicates either a sophisticated phishing campaign, exploitation of unpatched vulnerabilities, or insider assistance.
Analysts may also consider the geopolitical angle: targeting a hospital in Yemen could be opportunistic but may also intersect with regional cybercrime networks that operate across Middle Eastern countries. Cross-border investigations will be challenging due to varying legal frameworks and law enforcement capabilities.
Cybersecurity awareness is critical for mitigating such attacks. Hospitals must implement layered defenses, including endpoint detection, regular backups, employee training, and incident response protocols. International collaboration could also be key, as ransomware groups often operate transnationally, making unilateral efforts less effective.
Ultimately, the Abdulhadi Hospital case serves as a stark reminder that healthcare systems are increasingly lucrative targets for cybercriminals. The combination of sensitive data, operational pressure, and limited cyber resilience creates an environment where attackers can maximize leverage. Organizations must prioritize cybersecurity even in challenging operational environments to prevent disruptions that could cost lives.
Fact Checker Results:
✅ Reported by multiple cybersecurity news sources.
❌ No official confirmation from Abdulhadi Hospital or Yemeni authorities as of yet.
✅ Social media posts indicate the ransom demand and data size are consistent with similar ransomware attacks.
Prediction:
💰 If ransom negotiations proceed, payment may be made to prevent operational disruption, as hospitals often prioritize patient care over data security.
🔍 Increased monitoring by regional cybersecurity teams is likely, potentially leading to further exposure of Devman’s activities.
🛡️ The incident may accelerate investment in healthcare cybersecurity across Yemen and neighboring countries, emphasizing backups, employee training, and international cooperation.
🕵️📝✔️Let’s dive deep and fact‑check.
References:
Reported By: x.com
Extra Source Hub (Possible Sources for article):
https://stackoverflow.com
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2
Bing
🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]
📢 Follow UndercodeNews & Stay Tuned:
𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon




