Every two to three days, a new set of leaked passwords related to a Dutch hospital appears online.
That is not an exaggeration. It is what we found after scanning available data for a group of Dutch hospitals using our platform.
These leaked username and password combinations, generally called credentials, do not just belong to staff email. They open doors to internal systems, electronic patient records and access portals.
What we looked at
We analyzed breach files linked to a group of Dutch hospitals, spanning eight years, available on the dark web. The aim was to understand how common these leaks are, compare hospitals against each other, and show why this is a growing problem in healthcare.
The leaks happen in a few ways:
- Third-party misuse. A staff member uses their work email on a compromised website, a travel app or an online store.
- Service breaches. A vendor or system the hospital uses is hacked.
- Credential stealers. Malware captures login data silently.
- Phishing. Staff are tricked into entering credentials into a fake portal.
How much we are actually talking about
- On average, each hospital had 1,061 breach files associated with it.
- That is a new leak publication every two to three days, per hospital.
- The worst performer had over 2,000 separate leak files.
- Only one hospital in the group had zero known leaks.
These are not single passwords. Each file can hold dozens, sometimes thousands, of login details.
What it leads to
Leaked credentials can lead to compromise of personal healthcare data, exposure of internal systems, and loss of trust with the regulatory and reputational damage that follows. Attackers routinely use this data for initial access into an environment.
Given the volume, the frequency and the sensitivity of what sits behind these logins, we assess the risk as high, particularly for hospitals with above-average exposure and little or no monitoring in place.
What actually helps
There are effective steps available today, and they start with a real organization-wide password policy. That means more than requiring complex passwords. It involves:
- Clear rules on password reuse across personal and professional accounts, and yes, we know roughly three in four readers do reuse.
- Regular awareness training on phishing and credential misuse.
- Technical controls: password managers, and breach monitoring.
- Multi-factor authentication as a second layer wherever the system supports it.
A policy reduces risk substantially, but only when the basics are in place and enforced. Poor password habits, unmonitored exposure or unaware users still open the door.
Seeing it the way an attacker does
Our platform continuously scans breach sources on the dark web for credentials tied to an organization’s domain: alerts when users appear in breach data, peer comparison against the sector, and a map from an exposure to the attack paths it opens, whether phishing, internal reuse or a shared login.

