LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Doctors Regional Cancer Center Listed by incransom Ransomware Group

HIGH severity claimedUnverified claimHow we verify

Doctors Regional Cancer Center Listed by incransom Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·October 10, 2024
Doctors Regional Cancer Center Listed by incransom Ransomware Group

Reported October 10, 2024.

HIGH
Severity
October 10, 2024
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Doctors Regional Cancer Center was listed by the incransom ransomware group on October 10, 2024, after internal files were exfiltrated in a ransomware attack. An undisclosed number of individuals may be affected; anyone who received services from the center should review their statements and consider placing a fraud alert.

Severity & verification
HIGH severity claimedUnverified claim
Exposes medical data.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Patients and families who have sought care at Doctors Regional Cancer Center may now face uncertainty about whether personal or medical information was taken in a ransomware incident. On October 10, 2024, the organization appeared on a listing associated with the incransom ransomware group, which claimed that internal files had been exfiltrated. The number of people affected remains unknown, and public detail on the precise contents of those files is limited. For anyone who has received oncology services there, the practical concern is straightforward: sensitive health-related data, if exposed, can be misused for identity theft, fraud, or targeted scams long after the initial event.

This article sets out only what has been reported, places the claim in context, and outlines concrete steps people can take while more information is awaited.

Breaking down the breach

According to available reporting, Doctors Regional Cancer Center was listed by the incransom ransomware group on October 10, 2024. The group claims that internal files were exfiltrated as part of a ransomware attack. No public confirmation of the attack’s success, the volume of data taken, the exact date of intrusion, or the technical method used has been provided in the facts available. The number of individuals whose information may be involved is listed as unknown. In short, the public record consists of a leak-site listing and a statement that internal files were removed; everything else about timing, scale, and confirmation remains undisclosed.

Ransomware incidents of this type typically involve encryption of systems combined with data theft, after which the operators pressure the victim by threatening to publish the material. Because the facts do not confirm whether systems were encrypted, whether a ransom was demanded or paid, or whether any data has actually been released, those elements cannot be treated as established. Readers should regard the listing itself as a claim by the group rather than independent verification.

The group behind it: incransom

Incransom is a ransomware operation that has appeared in public reporting as a double-extortion actor. Groups of this kind commonly gain access to networks, steal data, encrypt systems, and then post victim names on dedicated leak sites to increase pressure. They typically demand payment in cryptocurrency and threaten to publish or auction the stolen material if their terms are not met. Prior activity attributed to similar operators has included targeting healthcare, professional services, and other sectors that hold sensitive records, because the potential disruption and regulatory exposure can make payment more likely.

Public knowledge of incransom’s general tactics does not extend to verified details of this specific incident. The group claims that Doctors Regional Cancer Center’s internal files were exfiltrated; that claim has not been independently confirmed in the material provided. No statements attributed to the group beyond the listing itself are part of the known facts, and no dollar amounts, file counts, or sample data releases have been reported here.

Who is Doctors Regional Cancer Center?

Doctors Regional Cancer Center is an oncology provider that has delivered cancer treatment services to its communities for more than thirty years. Reporting notes that it was the first program of its kind in the region and that, from 1987 onward, its team has guided patients and families through diagnosis, treatment, and recovery. Organizations of this type sit at the intersection of clinical care and personal data: they routinely handle medical histories, treatment plans, insurance details, contact information, and other records necessary to coordinate care.

A breach involving a cancer center is consequential because the data such facilities hold is both intimate and long-lived. Cancer care often spans months or years and involves multiple specialists, laboratories, and payers. Even when the exact contents of an incident remain unconfirmed, the sector’s typical holdings mean that any unauthorized access carries elevated risk for the individuals whose records may be involved and for the continuity of care the organization provides.

The information in question

The facts state that internal files were exfiltrated in a ransomware attack. No further breakdown of data types—such as patient names, medical records, financial information, employee data, or administrative documents—has been disclosed. The number of people affected is unknown. Therefore it is not possible to assert that any specific category of personal or clinical information was taken.

Healthcare providers of this kind typically maintain electronic health records, appointment and billing systems, insurance correspondence, and internal operational files. Those materials can include identifiers, diagnoses, treatment notes, and contact details. Because the exact contents of the claimed exfiltration remain unconfirmed, any discussion of exposure must stay at that general level: the organization holds the kinds of data one would expect of a long-standing oncology practice, and the group claims internal files were removed. Nothing more specific is established in the public facts.

What's at stake

For individuals, the primary risks are identity theft, medical identity fraud, and phishing or social-engineering attempts that exploit knowledge of a cancer diagnosis or treatment history. Stolen health data can be used to open fraudulent accounts, submit false insurance claims, or craft highly convincing scams. Even if clinical details are not present, contact information and administrative records can still enable account takeover or targeted harassment. Because the scale of the incident is unknown, it is impossible to say how many people face these risks; the prudent assumption for anyone who has been a patient or employee is that their information could be among the internal files claimed to have been taken.

For the organization, the stakes include operational disruption, regulatory scrutiny under healthcare privacy rules, potential notification obligations, and erosion of patient trust. Ransomware events can interrupt scheduling, billing, and clinical systems even when data theft is the more visible claim. None of these outcomes has been confirmed in the available facts; they are the ordinary consequences that follow when a healthcare provider is listed by a ransomware group.

If your data was in this claimed breach

Public detail remains limited, so the immediate priority is practical self-protection rather than waiting for complete disclosure. Consider the following steps:

Until more verified information is released, these measures remain the most direct way for affected individuals to reduce the chance that any exposed internal files are turned against them. The listing by incransom is a claim, the number of people involved is unknown, and the precise data types remain undisclosed; acting on that uncertainty with measured steps is the responsible course.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyDoctors Regional Cancer Center security record
87/100
DoxxScan™ · Low doxx risk
B 80Good record

1 reported incident on record.

See Doctors Regional Cancer Center’s full breach history →

More recent breaches

Community Connections Listed by incransom Ransomware GroupApril 4, 2026Onecare Listed by incransom Ransomware GroupDecember 15, 2024Primary Health Services Center Listed by incransom Ransomware GroupNovember 28, 2024Imperial Valley Respite (ivrespite.com) Listed by incransom Ransomware GroupNovember 3, 2024

Latest breaches

Read GalaxyWarden’s full analysis of the Doctors Regional Cancer Center Listed by incransom Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by incransom — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram