Harry Perkins Institute of medical research Listed by medusa Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The Harry Perkins Institute of medical research Listed by medusa Ransomware Group (reported July 7, 2024) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
When a medical research institute appears on a ransomware group's leak site, the immediate concern for staff, collaborators and anyone whose image or details might sit in its systems is straightforward: what personal or sensitive material could now be in the hands of criminals, and what practical risks follow. Public reporting places the Harry Perkins Institute of Medical Research on the Medusa ransomware group's listing as of 7 July 2024. The number of people affected remains unknown, and the precise scope of any compromise has not been independently confirmed beyond the group's own claims.
What is stated is that internal files were exfiltrated in a ransomware attack and that 4.6 TB of internal building camera recordings have been uploaded. For ordinary people connected to the institute—employees, research participants, visitors or partners—the practical stakes centre on whether footage, internal documents or related records could expose identities, movements or confidential work. Until fuller verification emerges, those potentially affected are left weighing limited public detail against the known habits of ransomware operators.
What happened
According to the available record, the Harry Perkins Institute of Medical Research was listed by the Medusa ransomware group on 7 July 2024. The listing characterises the incident as a ransomware attack in which internal files were allegedly exfiltrated. The group further claims that 4.6 TB of internal building camera recordings have been uploaded. No independent confirmation of the attack method, the exact date of intrusion, the total volume of other data taken, or the number of individuals affected has been supplied in the public facts. Scale beyond the stated 4.6 TB of camera footage and the broader category of “internal files” remains undisclosed. The institute itself is described as having 172 employees and a corporate office address listed as PO Box 7214, Australia.
In short, the public picture rests on the ransomware group's claim of a successful exfiltration and the subsequent appearance of the institute on its leak site. Timing of the initial compromise, any ransom demand, and whether systems were encrypted or merely stolen from are not detailed in the reported facts.
Inside medusa
Medusa is a well-documented ransomware operation that has operated for several years under a ransomware-as-a-service model. Public reporting consistently describes the group as targeting organisations across multiple sectors, encrypting systems where possible and, more critically, exfiltrating data for double-extortion purposes. Victims are typically listed on a dedicated leak site; if payment is not made, portions of the stolen data are published or auctioned. Medusa has previously claimed responsibility for attacks on healthcare, education, manufacturing and professional-services entities, often advertising large volumes of internal documents, databases and media files.
The group's typical tactics include initial access via phishing, exploited vulnerabilities or compromised credentials, followed by lateral movement, data staging and exfiltration before or alongside encryption. Its leak-site listings function as pressure tools; they are claims by the operators rather than verified admissions by the named organisations. In this instance, Medusa claims to have listed the Harry Perkins Institute and to have uploaded 4.6 TB of internal building camera recordings. No further specific statements by the group about this victim—such as ransom amounts or additional file categories—are contained in the provided facts, and none should be assumed.
Who is Harry Perkins Institute of medical research?
The Harry Perkins Institute of Medical Research is a leading Western Australian medical research centre dedicated to tackling major health issues. Organisations of this type conduct laboratory and clinical research, manage grant-funded projects, collaborate with hospitals and universities, and maintain administrative, facilities and security systems. With a reported staff of 172, the institute operates at a scale that routinely involves employee records, research data, visitor management and building infrastructure such as CCTV.
A breach at a medical research body is consequential because such institutions typically hold sensitive scientific information, personnel details and, in some cases, data linked to research participants or patients. Even when the primary claimed material is building camera footage, the presence of internal files raises the possibility that operational, financial or collaborative records could also be involved. Public trust in research organisations depends on the secure handling of both scientific work and the personal information of those who work in or visit their facilities.
What data was at risk
The facts name “internal files exfiltrated in ransomware attack” and specifically state that 4.6 TB of internal building camera recordings have been uploaded. No further breakdown of file types, databases or personal-data categories is provided. The number of people affected is listed as unknown.
Medical research institutes commonly hold employee identity and payroll information, access-control logs, research protocols, grant documentation, correspondence with partners, and security-camera archives that may capture staff, contractors and visitors. Camera recordings can reveal faces, vehicle details, entry and exit patterns and, in some cases, conversations if audio is present. Because the exact contents beyond the claimed camera footage remain unconfirmed, it is not possible to state with certainty which additional categories, if any, were taken. Readers should treat the 4.6 TB figure and the “internal files” description as the group's claim rather than independently audited fact.
The real-world impact
For individuals whose images appear in the claimed camera recordings, the concrete risks include potential identification, tracking of movements on site, and secondary use of footage for social engineering or doxxing. Staff may face elevated phishing risk if internal directories or organisational charts were among the broader “internal files.” Research collaborators could see proprietary or pre-publication material exposed, though no such specifics are confirmed here.
For the institute, the listing itself can disrupt operations, require forensic investigation, notification obligations under Australian privacy law, and reputational scrutiny. Even when the full extent is unknown, the combination of ransomware attribution and claimed large-scale media exfiltration typically triggers regulatory attention and the need to support potentially affected people. Because the number of people affected is unknown, the practical impact remains difficult to quantify; the absence of confirmed counts does not eliminate the possibility of real harm to those whose data or images were involved.
If your data was in this claimed breach
If you are a current or former employee, contractor, visitor or research participant connected to the Harry Perkins Institute, treat the Medusa listing as a prompt for caution rather than confirmed personal compromise. Monitor financial and email accounts for unusual activity, enable multi-factor authentication wherever available, and be alert to phishing messages that reference the institute or medical research. Consider placing fraud alerts with credit agencies if you believe identity documents could have been exposed. Because the exact data types beyond camera recordings are unconfirmed, avoid assuming the worst while still taking basic protective steps.
Readers can also run a free exposure scan of their email address to check whether their information has already surfaced in known breach data sets. Such checks do not prove involvement in this specific incident, but they provide a practical way to assess wider exposure and decide on further action.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
NORTHEAST OHIO NEIGHBORHOOD HEALTH SERVICES (NEON) Listed by medusa Ransomware GroupThe Crown Princess Mary Cancer Centre Listed by medusa Ransomware GroupNorth Los Angeles County Regional Center Listed by medusa Ransomware GroupBrodsky Renehan Pearlstein & Bouquet, Chartered Listed by medusa Ransomware GroupLatest breaches
Publicly posted by medusa — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.