A hundred million dollars is not what the operators expected to receive. It is what they said out loud, to a Japanese teaching hospital, in an attack reported in February 2026 and attributed to a group operating as NetRunner. The incident is described as affecting roughly 131,700 people.
This desk does not report ransom demands as fact, and does not grade severity on the size of one. Both rules exist for the same reason: the number originates entirely with the party demanding it, and there is no mechanism by which anyone else can verify it.
Why The Figure Gets Printed Anyway
A large demand is a free headline. It costs the group nothing to state, it cannot be checked, and it reliably produces coverage that describes the group as formidable. Repeat that enough and the demand functions as marketing to future affiliates rather than as a price.
The figure that carries information is the other one. Roughly 131,700 people had records in a hospital system that an extortion group reached. Each of those people has a real and durable exposure, and none of them will be told what was decided about the demand.
Hospitals Are Targeted For The Clock, Not The Money
Healthcare providers are attacked because the pressure to restore service is immediate and visible in a way it is not in most sectors. A manufacturer with encrypted systems loses output. A hospital with encrypted systems diverts patients. The urgency is the leverage.
That dynamic is why our severity grading weighs affected population, data sensitivity and operational disruption, and excludes the demand entirely. On those axes this file grades as serious. On the axis the group chose to advertise, it grades as nothing at all.
Compiled from public reporting, listed below. The demand figure originates with the attacking group and is labelled as a claim throughout; we have not seen it confirmed by the hospital. We do not know whether a payment was made. Corrections: corrections@forensicpost.com.