Pavillon, a residential and outpatient addiction treatment center located in the Blue Ridge Mountains of North Carolina, may have experienced a data security incident after a hacker group publicly claimed responsibility for a cyberattack on the organization. Treatment centers that handle sensitive medical and personal information about their patients have a responsibility to protect that information, and anyone affiliated with Pavillon deserves to know what is currently known, and not known, about this incident.
Pavillon’s Data Breach Investigation
According to a post identified on the dark web surveillance platform Ransomware.live, a hacker group calling itself Global Secret Group claimed on August 5, 2026, to have exfiltrated approximately 646 gigabytes of data from Pavillon. A separate cybersecurity monitoring outlet, HookPhish, similarly reported that Global Secret Group claimed responsibility for an attack on Pavillon around the same date. The incident is estimated to have occurred on or around August 5, 2026, based on the timing of the group’s public claim.
As of this writing, Pavillon itself has not issued a public confirmation of the incident, and no information has been made available about which specific individuals may be affected or what categories of personal or medical information the claimed attack may have compromised. Claims made by ransomware and extortion groups on dark web forums are not independently verified at the time they are posted, and companies frequently take additional time to investigate internally, confirm whether an intrusion actually occurred, and determine its scope before issuing any public notification.
Founded in 1996, Pavillon has provided residential and outpatient addiction treatment services to more than 9,000 individuals over its history. Addiction treatment centers and other behavioral health providers are attractive targets for data-theft groups because the records they maintain combine highly sensitive personal identifiers with equally sensitive substance-use and mental health treatment history, information that carries a heightened risk of harm to patients if it is exposed or published, given the particular stigma and privacy concerns attached to addiction treatment records.
Healthcare providers of all kinds have faced a wave of ransomware and data-extortion attacks in 2026, with multiple hacker groups publicly claiming credit for breaches at hospitals, specialty clinics, and treatment centers throughout the year. These groups frequently use the threat of publishing stolen data, rather than simply encrypting a victim’s systems, as leverage to try to extract a ransom payment, and they often post claims to dark web forums and leak sites well before, or even without ever waiting for, the affected organization’s own public confirmation.
Until Pavillon issues its own statement or formal notification, individuals who believe they may be affected, including current and former staff and patients, should treat this as an unconfirmed but credible report and take reasonable precautionary steps in the meantime. Monitoring for any official communication from Pavillon and remaining alert to potential follow-on scams referencing this reported incident are prudent steps regardless of whether formal confirmation follows.
When Did This Breach Occur?
The hacker group Global Secret Group’s public claim of responsibility was posted on or around August 5, 2026, and the underlying incident is estimated to have occurred around the same date. Pavillon has not yet issued its own public statement confirming a specific incident date.
What Information Was Breached?
The hacker group claimed to have exfiltrated approximately 646 gigabytes of data, but no specific categories of personal or medical information have been publicly confirmed by Pavillon or independently verified at this time.
What You Can Do
If you are a current or former Pavillon patient or staff member, consider taking the following precautionary steps while more information becomes available:
- Watch for any official notification from Pavillon regarding this reported incident.
- Monitor your financial accounts and any explanation-of-benefits statements for unauthorized activity.
- Consider placing a fraud alert or credit freeze with Equifax, Experian, and TransUnion as a precaution.
- Be cautious of phishing attempts referencing this reported breach, and never provide personal information to an unsolicited contact.
- Keep any communications you receive from Pavillon regarding this incident for your records.
File a Data Breach Lawsuit Against Pavillon
If you have been affected by the reported Pavillon data breach, or if you later receive a notification letter confirming your information was involved, you may have legal options available to you. Healthcare and treatment providers are expected to maintain reasonable safeguards to protect the sensitive personal and medical information of their patients and staff.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.