Georgia Dermatology & Skin Cancer Center Listed by qilin Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Georgia Dermatology & Skin Cancer Center was listed by the Qilin ransomware group on December 26, 2025, with internal files reported as exfiltrated. Individuals who may have received care there are advised to check for breach notices and monitor their accounts.
Inside the incident
The only confirmed public detail is the appearance of Georgia Dermatology & Skin Cancer Center on the qilin ransomware group's leak site. The group claims to have exfiltrated internal files. No information has been released about the date of the intrusion, the method of access, the volume of data involved, or whether any files were subsequently published. The number of people whose information may be affected is not known.
Who is qilin?
Qilin is a ransomware group that has conducted operations since at least 2022. Public reporting describes it as operating a ransomware-as-a-service model in which affiliates deploy encryption tools and, in many cases, also remove data from targeted networks. The group maintains a leak site where it lists organizations and, at times, posts samples or full archives of claimed stolen material. Its targets have included entities in multiple sectors; listings on the site represent the group's assertions rather than independently verified events.
Georgia Dermatology & Skin Cancer Center and its sector
Georgia Dermatology & Skin Cancer Center provides medical services focused on skin conditions and oncology. Organizations of this type routinely maintain electronic health records, appointment histories, billing information, and identifiers required for insurance and regulatory compliance. A breach at a medical practice can expose data that is both personal and difficult to change, such as diagnostic details and treatment records.
What data was at risk
The available information states only that internal files were claimed to have been taken. The specific categories of data have not been disclosed. Healthcare providers typically store patient names, dates of birth, contact details, medical histories, insurance information, and clinical notes; whether any of these elements were among the claimed files cannot be confirmed from public sources.
Why it matters
Medical and personal data held by specialty practices can be used for identity-related fraud, insurance misuse, or targeted scams. When such information leaves organizational control, affected individuals may face prolonged monitoring needs and administrative burdens. For the organization, the incident adds to the regulatory and operational requirements that follow any confirmed or claimed exfiltration of internal records.
Were you affected?
Patients and staff of Georgia Dermatology & Skin Cancer Center have no public confirmation of exposure at this time. Practical steps include:
- Contacting the practice directly for any official notifications or guidance it may issue.
- Reviewing statements from health insurers and credit-reporting agencies for unusual activity.
- Running a free exposure scan of your email address against known breach datasets to check for prior appearances of your information.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Shore Gardens Rehabilitation & Nursing Center Listed by qilin Ransomware GroupThe Blood and Marrow Transplant Group of Georgia Listed by qilin Ransomware Group1sthealthinc.com Listed by qilin Ransomware GroupThe Holiday:Adult Care Community & Retirement Homes Listed by qilin Ransomware GroupLatest breaches
Publicly posted by qilin — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.