Expert MRI Data Breach Exposes Patient Information
Get our Quarterly Ransomware Report as a PDF June saw 102 publicly disclosed ransomware attacks across 21 countries, with Australia experiencing a particularly active month at 21 attacks.
Key points
- Unauthorized access and data exfiltration occurred between August 14 and August 24, 2025.
- Exposed data includes PII and PHI: names, addresses, DOB, medical info, and SSNs.
- PEAR ransomware group claimed responsibility.
Connected intelligence
Signal brief
Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.
Organization
- Published
- Aug 24, 2025
- Updated
- Jul 22, 2026
- Confidence
- Medium
- Evidence
- 1 source
Structured assessment
Signal analysis
This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.
Threat source
The feed marks multiple actor roles. Treat this as a review signal rather than a final attribution.
- Source type: possible insider or internal misuse
- Source type: supplier or third-party involvement
Business impact
- Impact area
- Confidentiality, Availability
- Likely asset
- User or customer data, Server or cloud data store
Mentioned entities
Quick context
Questions about this signal
What happened in this signal?
Get our Quarterly Ransomware Report as a PDF June saw 102 publicly disclosed ransomware attacks across 21 countries, with Australia experiencing a particularly active month at 21 attacks. Healthcare remained the top target with 30 incidents, followed by services with 15 and education with 14. The ransomware ecosystem also continued to fragment, with 31 groups claiming victims. The newly emerged 2019 ransomware group led the month with 12 claimed victims, making it one of June’s most notable developments. 1. The Melbourne International Film Festival (MIFF) suffered a data breach after attackers compromised its third-party ticketing provider, Ferve, exposing the personal information of around 26,700 customers. While payment card details and passwords were not affected, names, email addresses, phone numbers and residential addresses were potentially accessed. Ransomware group 2019 has claimed responsibility for the attack and allegedly advertised a much larger dataset for sale, although MIFF disputes those claims and the attribution remains unverified. 2. VSP Solutions , an Australian distributor of video security products, confirmed it is investigating a cyber incident after the Stormous ransomware group claimed responsibility for the attack. Stormous alleges it stole more than 40 GB of sensitive data, including financial records, email archives and customer databases, although VSP says the compromised information was historical and that business operations were not disrupted. The company has engaged forensic experts and notified the relevant authorities while its investigation continues. 3. The UN World Food Programme (WFP) disclosed that a cyberattack exposed the personal data of approximately 600,000 households in Gaza after attackers compromised its Palestine self-registration platform. The exposed information included names, ID numbers, mobile phone numbers, and location data used to register for food and cash assistance. WFP took the affected system offline, launched an investigation, and stated that no ransomware group had claimed responsibility for the attack. 4. IMA Diligence Services confirmed it had notified 525,306 individuals that their personal information was compromised in a December 2025 cyberattack involving a legacy server hosted by a third-party provider. The exposed data included Social Security numbers, financial information, medical records, and government-issued IDs. Genesis ransomware group claimed responsibility for the attack, alleging it stole 700 GB of data, although the company did not confirm the attribution or the volume of data reportedly exfiltrated. 5. More than 3,100 individuals were notified by Bronsky Orthodontics after unauthorized access to multiple employee email accounts exposed protected health information. The compromised data included patient names, dates of birth, contact information, dental and orthodontic treatment records, insurance information, and, for a limited number of individuals, Social Security numbers, financial account information, and government-issued IDs. The practice said it secured the affected accounts, completed a forensic investigation, and is reviewing its data privacy and security policies. 6. Hampr , an Australian workplace catering provider, said it was investigating claims that a ransomware group had stolen and published more than 360,000 customer records on a hacking forum. 2019 ransomware group alleged the leaked data included customer IDs, names, mobile phone numbers, account details, dietary preferences, payment information, billing data, and workspace details. Hampr said it had notified customers and relevant cybersecurity authorities while its investigation remained ongoing, and the claims had not been independently verified. 7. Bridle Trails Family Dentistry disclosed that 20,976 current and former patients were affected by a data breach stemming from the compromise of an employee email account in November 2024. The potentially exposed information included names, dates of birth, Social Security numbers, medical and treatment records, medical record numbers, health insurance information, driver’s license numbers, and taxpayer ID numbers. The practice said it was unaware of any misuse of the data and has enhanced its security measures. 8. A ransomware attack against the National Federation of Subpostmasters (NFSP) disrupted communications with the UK Post Office after attackers exploited a critical cPanel vulnerability. The attackers encrypted the federation’s website files and demanded a ransom, prompting the Post Office to temporarily suspend email communications with the NFSP as a precaution. While the incident caused ongoing operational disruption, the NFSP said its investigation found no evidence that data had been lost or exfiltrated. 9. More than 25,000 Australian Centre for the Moving Image (ACMI) customers were allegedly impacted after ransomware group 2019 claimed to have breached the organization’s systems and published customer data on a hacking forum. The actor alleged the stolen data included names, email addresses, dates of birth, gender, sign-in details, invoicing information, and IP addresses. ACMI said it was investigating a separate breach involving a third-party system used for its Cinema 3 streaming service, emphasized that payment card details and passwords were not compromised, and had not confirmed the group’s claims. 10. IKEA said it was investigating claims that the LAPSUS$ extortion group had stolen and was attempting to sell 180 GB of internal data allegedly taken from Ingka Group , the retailer’s largest franchisee. The ransomware group claimed the data included source code repositories, e-commerce architecture, supply chain systems, cloud infrastructure, and AI/MLOps projects, but there was no evidence that customer data was involved. IKEA had not confirmed the breach or the authenticity of the claims at the time of publication. 11. An unauthorized third party accessed and exfiltrated customer data from Australian luxury fashion brand Camilla , prompting the company to confirm a cyber incident affecting its Australian operations. The compromised information included customer names, dates of birth, email addresses, and phone numbers stored in its point-of-sale system, while payment card and banking information were not affected. Camilla said it notified impacted customers and the Office of the Australian Information Commissioner, and that business operations continued without disruption while the investigation remained ongoing. 12. More than 17,300 MMJ Real Estate clients may have had their personal data exposed after 2019 ransomware group claimed to have breached the Australian real estate agency and posted the data on a hacking forum. The allegedly compromised records included full names, email addresses, mobile numbers, addresses, business interests, property price ranges, and inquiry timestamps.
When was this signal reported?
Shadow Tier lists Aug 24, 2025 as the signal date.
Which organization is connected to this signal?
Expertmri is the organization connected to this public signal.
Explore ExpertmriWhich attack pattern is relevant?
This signal is connected to current ransomware incidents based on its reported incident context.
Explore current ransomware incidentsWhich impact area is relevant?
This signal is connected to data exposure and breach intelligence based on its reported consequences.
Explore data exposure and breach intelligence