LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surface
Recent BreachesData breach tracker

Recent Breaches › Clarke Radiology Listed by thegentlemen Ransomware Group

HIGH severity claimedUnverified claimHow we verify

Clarke Radiology Listed by thegentlemen Ransomware Group: What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·July 23, 2026
Clarke Radiology Listed by thegentlemen Ransomware Group

Reported July 23, 2026.

HIGH
Severity
1
Data types exposed
July 23, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Clarke Radiology was listed today by thegentlemen ransomware group after internal files were taken during a ransomware attack. An undisclosed number of people may be affected; anyone who received services from the provider should check for updates and take appropriate protective steps.

Severity & verification
HIGH severity claimedUnverified claim
Exposes medical data.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Was your email in the Clarke Radiology Listed by thegentlemen Ransomware Group breach?
See every leak tied to your email — not just this one. 15-second check, no card, no account.

When a medical imaging centre appears on a ransomware group's listing, the immediate concern is not abstract cybersecurity — it is the personal information of patients who trusted that centre with scans, referrals, and health details. For people who have used Clarke Radiology, the practical question is whether their records were among internal files the attackers claim to have taken, and what that could mean for privacy and fraud risk in the months ahead.

Public reporting on 23 July 2026 stated that Clarke Radiology had been listed by the ransomware group known as thegentlemen. The number of people affected remains unknown, and the precise contents of any taken material have not been fully detailed beyond a claim of internal files exfiltrated in a ransomware attack. What is known is limited; what matters is how patients and staff can respond calmly and usefully.

What happened

According to public reporting dated 23 July 2026, Clarke Radiology was listed by thegentlemen ransomware group. The available account describes internal files as having been exfiltrated in a ransomware attack. No confirmed figure has been published for how many individuals may be involved, and the method of initial access, the duration of any intrusion, and the full scope of systems touched have not been disclosed in the material provided.

A leak-site listing by a ransomware group is a claim by that group. It does not by itself prove every asserted detail, nor does it automatically confirm that every category of data held by the organisation was copied. Independent verification of volume, exact file types, and whether encryption or other disruption occurred on the organisation's systems has not been set out in the reported facts. Timing beyond the 23 July 2026 report date is likewise undisclosed.

Who is thegentlemen?

thegentlemen is a ransomware group known in public reporting for double-extortion style operations: encrypting or threatening systems while also claiming to steal data and pressuring victims by listing them on a dedicated leak site. Like other groups in this category, it typically advertises victims, sets deadlines, and threatens to publish or auction stolen material if demands are not met. Public coverage of such groups has described use of common initial-access paths — including compromised credentials, exposed remote services, and phishing — followed by lateral movement and data staging before ransom notes appear.

Nothing in the facts supplied here quotes specific demands, deadlines, or sample files that thegentlemen may have posted about Clarke Radiology beyond the listing itself and the characterisation of internal files exfiltrated in a ransomware attack. Those operational patterns are drawn from the group's established public profile, not from unverified claims unique to this incident. Readers should treat the group's listing as an assertion that requires corroboration from the organisation or regulators where possible.

Who is Clarke Radiology?

Clarke Radiology, also referred to in public business listings as Clarke Medical Imaging Center, is a medical imaging facility based in Montreal, Quebec. Public descriptions state that it has more than forty years of experience and offers diagnostic services including X-rays, MRI, ultrasound, mammography, bone density scans, and cortisone injections. Such centres sit at a sensitive point in the healthcare chain: they receive referrals, schedule patients, capture images, and produce reports that feed back to referring physicians.

Organisations of this type routinely handle identity data, contact details, provincial health numbers or insurance identifiers, clinical history relevant to imaging, appointment records, and the images and reports themselves. A breach involving a radiology provider is consequential because the data is both personal and medical. Even when the exact files taken are unconfirmed, the sector's normal holdings explain why patients pay close attention when a listing appears.

What data was at risk

The facts name the exposed material as internal files exfiltrated in a ransomware attack. They do not publish a detailed inventory of fields, folders, or record counts. People affected are listed as unknown. It is therefore not possible to state as fact that any particular patient's MRI report, referral letter, or billing file was included.

In general, medical imaging centres hold demographics, contact information, health-card or insurer details, referral and appointment data, clinical notes tied to examinations, and diagnostic images and reports. They may also hold staff and contractor records, vendor contracts, and internal operational documents. Those categories are typical for the sector; they are not a confirmed contents list for this incident. Until Clarke Radiology or an official notice specifies what was taken, the exact data at risk remains unconfirmed beyond the broad description of internal files.

The real-world impact

For individuals, the main risks are misuse of personal and health-related information: targeted phishing that references a real appointment or scan, attempts at medical identity fraud, or exposure of sensitive clinical details if files are published or traded. Even partial records — a name, date of birth, and a procedure type — can make social-engineering attempts more convincing. Financial account takeover is less automatic than with payment-card breaches, but secondary fraud remains possible if identity documents or insurer numbers were in the same repositories.

For the organisation, a ransomware-related listing can mean operational disruption, cost of investigation and recovery, regulatory notification duties, and loss of patient trust. Accredited care settings are expected to protect health information; a claimed exfiltration puts pressure on incident response, patient communication, and any contractual obligations to partners and insurers. None of this establishes negligence as a proven fact; it describes the ordinary consequences when internal files are alleged to have left a healthcare environment.

Because the count of affected people is unknown and the file inventory is not public, impact will vary. Some patients may never appear in any stolen set; others may only learn later through an official notice. Calm monitoring beats panic: watch for unexpected medical bills, unfamiliar insurance activity, and emails that lean on radiology or Montreal clinic details to create urgency.

Were you affected?

If you have been a patient or staff member at Clarke Radiology, treat the listing as a reason to heighten caution rather than as proof that your file was copied. Prefer official notices from the clinic or from privacy regulators over unverified posts. Review account statements and health-insurance correspondence for activity you do not recognise. Be sceptical of unsolicited calls or messages that cite a scan, report, or “breach refund.” Use unique passwords and multi-factor authentication on email and patient portals where available. Consider a credit or fraud alert if your jurisdiction makes that straightforward and if you later receive confirmation that identity data was involved.

You can also run a free exposure scan of your email address to check whether that address has already appeared in known breach datasets elsewhere. That check does not confirm or deny inclusion in this specific incident, but it helps you see whether your credentials or contact details are already circulating and where to focus password changes first. Stay with primary sources for updates on Clarke Radiology; public detail on scale and exact data types remains limited.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyClarke Radiology security record
64/100
DoxxScan™ · Moderate doxx risk
B- 76Above-average record

1 reported incident on record.

See Clarke Radiology’s full breach history →

More recent breaches

Title Resources Listed by thegentlemen Ransomware GroupJuly 23, 2026HBS Group Listed by thegentlemen Ransomware GroupJuly 23, 2026Wunschkind Klinik Dr Brunbauer Listed by thegentlemen Ransomware GroupJuly 23, 2026TC Printing Listed by thegentlemen Ransomware GroupJuly 23, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the Clarke Radiology Listed by thegentlemen Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by thegentlemen — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram