LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › First Coast Heart Vascular Center Listed by thegentlemen Ransomware Group

HIGH severity claimedUnverified claimHow we verify

First Coast Heart Vascular Center Listed by thegentlemen Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·August 14, 2026
First Coast Heart Vascular Center Listed by thegentlemen Ransomware Group

Reported August 14, 2026.

HIGH
Severity
August 14, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

First Coast Heart Vascular Center was listed by thegentlemen ransomware group on August 14, 2026, with an undisclosed number of individuals’ personal data reportedly exposed. If you are a current or former patient, review the provider’s notice and consider placing a fraud alert or credit freeze while confirming whether your information was affected.

Severity & verification
HIGH severity claimedUnverified claim
Exposes medical data.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

On August 14, 2026, the ransomware group known as thegentlemen listed First Coast Heart Vascular Center on its leak site. That listing is an unverified claim by the group. As of writing, First Coast Heart Vascular Center has not publicly confirmed any incident, and independent confirmation from regulators or established breach indexes is not part of the available record. How many people may be affected and what, if any, data types were involved remain undisclosed in the listing details provided.

For patients and partners of a cardiovascular practice serving Northeast Florida, a leak-site claim matters because healthcare organizations routinely hold sensitive personal and clinical information. Until the organization or another authoritative source addresses the claim, the public record consists of the group's assertion and limited open description of the practice—not a confirmed inventory of stolen files.

Inside the listing

The available record states that First Coast Heart Vascular Center was listed by thegentlemen, with the report dated August 14, 2026. The number of people affected is unknown. Data types named as exposed are not disclosed. Method of access, timing of any intrusion, ransom demands, file volumes, and sample material are not described in the facts at hand.

Public material associated with the organization notes firstcoastheart.com and a business directory entry describing First Coast Heart & Vascular Center as a cardiovascular care provider in Northeast Florida, with services spanning cardiology, electrophysiology, advanced imaging, and vascular surgery. Those details describe the practice's public profile; they do not confirm that systems were compromised or that any particular records left the organization. The listing should be read as the group's claim, not as a verified breach report.

Who is thegentlemen?

thegentlemen is known in public reporting as a ransomware and extortion actor that pressures organizations by encrypting systems and by threatening to publish data on a leak site if demands are not met. Like other groups in this category, it typically advertises victims on a dedicated site, sometimes with countdowns or purported file samples, as part of an extortion narrative. Those patterns are drawn from the group's broader, well-documented public activity and do not by themselves prove what happened in any single case.

For this listing, the facts do not include specific statements from thegentlemen beyond the act of naming First Coast Heart Vascular Center. Claims about scale, content, or impact that appear only on criminal leak infrastructure should be treated as unverified marketing by the claimant until corroborated.

About First Coast Heart Vascular Center

First Coast Heart Vascular Center is described in public materials as a premier cardiovascular care provider serving patients across Northeast Florida. Its public website messaging emphasizes cardiology, electrophysiology, advanced imaging, vascular surgery, evidence-based treatments, and minimally invasive procedures aimed at heart and vascular health.

Organizations in this sector sit at the intersection of clinical care and regulated health information. They typically maintain scheduling systems, electronic health records, imaging and procedure documentation, billing and insurance workflows, and communications with referring physicians and hospitals. A credible compromise at such a practice would be consequential because the data involved is often both personally identifying and medically sensitive. That sector context explains why a leak-site claim draws attention; it does not establish that this claim is accurate.

What was likely exposed

The facts state that data types named as exposed are not disclosed. It is therefore not possible to assert what, if anything, was taken. No file counts, record categories, or sample descriptions are provided in the material used for this article.

If files from a cardiovascular practice were ever obtained by an unauthorized party, organizations of this kind typically hold combinations of patient identifiers, contact details, insurance and billing data, clinical notes, test results, procedure histories, and sometimes employee or vendor information. Those are sector norms, not a confirmed inventory for this listing. Readers should treat any specific “what was allegedly stolen” narrative that lacks independent confirmation as unproven.

Why it matters

Leak-site listings create uncertainty for patients even when the underlying claim is unconfirmed. If personal or clinical data were involved, risks could include targeted phishing that references real appointments or conditions, attempts at medical identity fraud, or misuse of insurance and billing details. If employee or business-contact data were involved, similar social-engineering risks can extend to staff and partners. None of those outcomes is established by a listing alone.

For the organization, an extortion group's public naming can affect trust, trigger contractual notice obligations if a real incident is later confirmed, and require careful internal investigation. For the public, the responsible stance is to separate the fact of a criminal claim from the unproven content of that claim, and to take proportionate precautions without assuming the worst as settled fact.

Steps worth taking either way

If you are a patient, former patient, or employee and you are concerned that your information might appear in criminal hands, act on a conditional basis. Watch for unexpected emails, texts, or calls that pressure you for credentials, payment, or urgent “medical” or “billing” action; verify through official channels you already trust rather than links or numbers in the message. Review explanation-of-benefits statements and insurance portals for unfamiliar claims. Consider placing a fraud alert or credit freeze with the major credit bureaus if you believe identity data could be at risk. Use unique passwords and multi-factor authentication on email and patient-portal accounts so a single exposed password is less useful.

If First Coast Heart Vascular Center or a regulator later publishes confirmed guidance, follow that notice for timelines, affected populations, and official support. In the meantime, a leak-site listing alone does not prove your records were taken. You can also run a free exposure scan of your email address to check whether that address has already appeared in other known breach datasets, which is a practical hygiene step regardless of whether this particular claim is ever substantiated.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyFirst Coast Heart Vascular Center security record
84/100
DoxxScan™ · Low doxx risk
B- 76Above-average record

1 reported incident on record.

See First Coast Heart Vascular Center’s full breach history →
RelatedMore incidents at First Coast Heart Vascular Center

More recent breaches

AnMed Listed by thegentlemen Ransomware GroupAugust 10, 2026Hoang Chiropractic Center Listed by thegentlemen Ransomware GroupAugust 7, 2026Advantage Home Health Care Listed by thegentlemen Ransomware GroupJuly 17, 2026Gene Codes Forensics Listed by thegentlemen Ransomware GroupJuly 11, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the First Coast Heart Vascular Center Listed by thegentlemen Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by thegentlemen — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram