Saturday, 29 November 2025
30.9 C
Singapore
29.9 C
Thailand
27.5 C
Indonesia
28.6 C
Philippines

UK healthcare provider HCRG confirms cyberattack after ransomware gang claims data theft

UK healthcare provider HCRG Care Group confirms a cyberattack after the Medusa ransomware gang claims to have stolen sensitive employee and patient data.

HCRG Care Group, one of the UK’s largest independent healthcare providers, has confirmed investigating a cybersecurity breach after a notorious ransomware group claimed to have stolen a large amount of sensitive data.

The healthcare organisation, formerly Virgin Care and now owned by Twenty20 Capita, provides various community health and social care services across the UK. It partners with NHS trusts and local authorities to deliver essential services, including urgent care, sexual health clinics, and adult and child social care support.

This week, HCRG was listed on the Medusa ransomware gang’s dark web leak site. The group claims to have infiltrated the company’s systems and stolen over two terabytes of data. If true, this could pose a serious risk to employees and patients.

Sensitive data potentially compromised

According to samples of the alleged stolen files shared by Medusa, the data may include employees’ personal details, sensitive medical records, financial information, and government-issued documents such as passports and birth certificates.

Alison Klabacher, a spokesperson for HCRG, confirmed in an email statement that the company is “currently investigating an IT security incident” and has “recently identified a post on the dark web by a group claiming responsibility.”

While HCRG has not confirmed the data type affected, Medusa’s claims have not been denied. The organisation has also not disclosed how many individuals may be impacted. HCRG employs over 5,000 staff and provides care to around half a million patients across the country, making the scale of the potential breach significant.

“Our team has not observed any suspicious activity since the implementation of immediate containment measures, and we are working with external forensic specialists to investigate the incident,” the spokesperson said. HCRG has also informed the UK’s Information Commissioner’s Office (ICO) and other regulators about the breach.

Despite the cyberattack, HCRG reassured the public that its services remain operational. “Our services are continuing to operate and safely see patients, and those with appointments or who need to access our services should continue to do so,” the company added.

Ransom demand and ongoing risks

The Medusa ransomware gang is demanding a US$2 million ransom to prevent the publication of the allegedly stolen data. HCRG has not confirmed whether it will negotiate with the hackers or pay the ransom.

It is still unclear how Medusa breached HCRG’s systems, but the group is known for exploiting unpatched vulnerabilities in remote desktop software. Cybersecurity experts warn that organisations handling sensitive information must remain vigilant against these attacks, which are becoming increasingly common in the healthcare sector.

As investigations continue, affected individuals may face identity theft and fraud risks. Patients and employees are urged to stay alert for any signs of misuse of their personal information.

Hot this week

Singapore consumers show growing interest in AI shopping companions

Research shows rising consumer interest in AI shopping agents in Singapore, with strong demand for cost savings and secure automation.

Asia’s boards place AI and digital transformation at the top of 2026 priorities

Nearly half of Asia’s governance leaders plan to prioritise AI in 2026 as digital transformation reshapes board agendas.

Nintendo acquires Bandai Namco Studios Singapore

Nintendo acquires Bandai Namco Studios Singapore to boost game development and expand its subsidiary network.

Square Enix revisits a classic with Dragon Quest VII: Reimagined

Square Enix unveils Dragon Quest VII: Reimagined, a modern remake featuring new visuals, streamlined storytelling, and updated combat.

Andika Rama returns to claim TGR Asia Esports GT Championship 2025 title

Indonesia’s Andika Rama wins the TGR Asia Esports GT Championship 2025 as his team seals both individual and country titles.

SMRT upgrades Bishan Depot with automation to double train overhaul capacity

SMRT upgrades Bishan Depot with automation to double overhaul capacity and enhance safety, efficiency, and workforce sustainability.

Apple is expected to overtake Samsung as the world’s leading smartphone maker

Apple is projected to overtake Samsung as the world’s top smartphone maker, driven by strong iPhone 17 demand and upcoming device launches.

Singapore orders Apple and Google to stop spoofed government identities on messaging apps

Singapore orders Apple and Google to block spoofed government identities on messaging apps to curb rising impersonation scams.

Nintendo acquires Bandai Namco Studios Singapore

Nintendo acquires Bandai Namco Studios Singapore to boost game development and expand its subsidiary network.

Related Articles

Popular Categories