Expert MRI Listed by pear Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Expert MRI has been listed by the pear ransomware group after internal files were exfiltrated in an attack, the disclosure emerging on September 02, 2025. An undisclosed number of people may have been affected; anyone connected to the organization should check for notifications and consider protective steps.
People who have used Expert MRI for diagnostic imaging may now face uncertainty about whether their personal and medical information has been taken by criminals. On September 02, 2025, the organization appeared on a listing associated with the pear ransomware group, which claims to have stolen internal files. The number of people affected remains unknown, and public detail about exactly what was taken is limited, yet any exposure of health-related records carries lasting practical consequences for patients and staff alike.
Medical imaging providers routinely handle names, contact details, insurance information, clinical histories, and scan results. When a ransomware group asserts it has exfiltrated internal files, those whose data may sit inside those files need clear, calm information about what is known, what is not, and what steps they can take.
What happened
According to available reporting, Expert MRI was listed by the pear ransomware group on September 02, 2025. The group claims that internal files were exfiltrated during a ransomware attack. No public confirmation has established the precise date the intrusion began, how the attackers gained access, or the total volume of data involved. The number of people affected is unknown. Public detail is limited to the claim that internal files were taken and that the organization has been named on the group’s leak-site listing. Whether any ransom demand was made, paid, or refused has not been disclosed in the facts available.
Ransomware incidents of this type typically involve unauthorized access followed by encryption of systems and the theft of data for leverage. In this case, only the listing and the assertion of exfiltrated internal files have been reported; further technical or forensic specifics remain undisclosed.
Inside pear
Pear is a ransomware group that operates in the manner common to many modern extortion crews: it claims to breach networks, steal data, encrypt systems, and then pressure victims by threatening to publish the stolen material on a dedicated leak site. Like other groups in this category, pear’s public activity consists largely of posting victim names and, at times, samples or full archives of purported data. These listings are claims made by the group itself and should be treated as unverified until independently confirmed.
Public knowledge of pear’s broader operations includes the use of double-extortion tactics—combining encryption with data theft—and the targeting of organizations across multiple sectors. No additional statements by pear specifically about Expert MRI beyond the listing itself are part of the reported facts. The group’s history of similar claims against other entities is well-documented in open sources, but those prior incidents do not automatically prove the accuracy or completeness of any single new listing.
About Expert MRI
Expert MRI is described as a provider of advanced diagnostic imaging focused on the brain, neck, spine, and orthopedic conditions. Organizations of this kind sit at the intersection of healthcare delivery and specialized medical technology. They schedule patients, capture and store high-resolution scans, generate reports for referring physicians, and manage billing and insurance workflows.
Because of that role, such practices typically maintain electronic health records, appointment systems, imaging archives, and administrative databases. A breach at an imaging center is consequential precisely because the data involved is both personally identifiable and clinically sensitive. Patients often share detailed medical histories and undergo procedures that produce permanent digital records; staff and referring clinicians also appear in internal correspondence and scheduling systems. The loss or exposure of those materials can affect trust, continuity of care, and regulatory obligations that apply to healthcare entities.
What was likely exposed
The facts state that internal files were exfiltrated in a ransomware attack. No further breakdown of file types, patient counts, or specific data categories has been publicly disclosed. Exact contents therefore remain unconfirmed.
Organizations that perform diagnostic imaging commonly hold patient names, dates of birth, addresses, telephone numbers, email addresses, insurance identifiers, clinical notes, referral information, and the imaging studies themselves. They may also store employee records, vendor contracts, and internal operational documents. While these categories are typical for the sector, it is not established that every such category was present in the files claimed by pear. Readers should treat any assertion about precise data elements as provisional until official notifications or forensic reports provide greater clarity.
Why it matters
For individuals, the practical risks include identity theft, medical identity fraud, targeted phishing that references real clinical details, and long-term anxiety about the permanence of exposed health information. Medical data cannot be changed the way a password can; once it is outside the organization’s control, it may circulate indefinitely among criminals. Even if the files prove to contain only administrative material, the mere possibility of clinical exposure can erode confidence in the provider and complicate future care.
For Expert MRI, the incident raises operational, legal, and reputational issues. Healthcare organizations face notification duties under privacy regulations, potential regulatory scrutiny, and the cost of investigation, remediation, and patient support. Disruption to imaging services can delay diagnoses and treatment for people who rely on timely scans. None of these consequences requires assuming negligence; they follow from the nature of the data and the sector itself.
If your data was in this claimed breach
If you have been a patient or employee of Expert MRI, begin by watching for any official notice from the organization describing what was affected and what support is offered. Place fraud alerts with the major credit bureaus, monitor financial and insurance statements for unexpected activity, and be cautious of unsolicited calls or emails that reference medical appointments or imaging results. Consider changing passwords on any accounts that reused credentials associated with the practice, and enable multi-factor authentication wherever possible.
You can also run a free exposure scan of your email address to check whether your information has already appeared in known breach data sets. Doing so provides an early signal if your details surface elsewhere, even while the full scope of this particular incident remains incompletely documented. Stay alert to further official updates rather than relying solely on claims made by the ransomware group.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Iroquois Memorial Hospital Listed by pear Ransomware GroupMedical Center, LLP Listed by pear Ransomware GroupWestern Orthopaedics Listed by pear Ransomware GroupBrevard Skin Listed by pear Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Expert MRI Listed by pear Ransomware Group →
Publicly posted by pear — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.