Mulkay Cardiology Consultants Listed by noescape Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The Mulkay Cardiology Consultants Listed by noescape Ransomware Group (reported September 2, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
Ransomware groups continue to target healthcare and specialty medical practices, treating clinical networks as high-value sources of both operational disruption and sensitive personal data. Listings on extortion sites remain a common pressure tactic even when independent confirmation is limited. Against that backdrop, Mulkay Cardiology Consultants appeared on a noescape leak site in early September 2023, with the group claiming a successful encryption and data-theft attack.
Public reporting on the incident is sparse. What is known comes largely from the threat actor’s own statements and secondary notices that the practice had been listed. The number of people affected has not been disclosed, and the precise contents of any stolen material remain only partially described. For patients and staff, the episode still warrants attention because cardiology practices routinely handle medical histories, contact details and administrative records that can be misused long after an initial intrusion.
Breaking down the breach
According to available notices, Mulkay Cardiology Consultants was listed by the noescape ransomware group on or about 2 September 2023. The group asserted that the practice’s network had been successfully encrypted and compromised and that approximately 60 GB of confidential and personal material had been taken. Beyond that claim, public detail is limited. No independent confirmation of the encryption event, the exact date of intrusion, the initial access method or the full scope of systems affected has been released in the materials provided. The number of individuals whose information may have been involved is recorded as unknown. The only data description offered is that internal files were allegedly exfiltrated in a ransomware attack.
Because the primary source for the volume and character of the data is the threat actor’s own listing, those assertions should be treated as unverified claims rather than established fact. No further technical indicators, ransom demands or negotiation outcomes have been made public in the record at hand.
Who is noescape?
noescape was a ransomware operation that gained visibility in 2023 through a double-extortion model: encrypting victim systems while simultaneously copying data and threatening to publish it on a dedicated leak site if payment was not made. The group typically operated as a ransomware-as-a-service, recruiting affiliates who conducted intrusions and shared proceeds. Public reporting from that period described common tactics such as exploitation of exposed remote-access services, credential theft and rapid deployment of encryptors once footholds were established. Victims spanned multiple sectors, including professional services and healthcare-related organisations. noescape’s leak site served both as a pressure mechanism and as a public catalogue of claimed victims. In this instance the group’s listing of Mulkay Cardiology Consultants constitutes its claim of responsibility and of data possession; it does not by itself constitute independent verification of every detail asserted.
About Mulkay Cardiology Consultants
Mulkay Cardiology Consultants is a cardiology practice founded more than a decade ago by Angel J. Mulkay, MD, a cardiac and peripheral interventionalist. Organisations of this type provide diagnostic, interventional and ongoing care for patients with heart and vascular conditions. They typically maintain electronic health records, scheduling and billing systems, referral correspondence and staff administrative files. Because the practice sits at the intersection of clinical care and personal identity data, any confirmed compromise carries consequences that extend beyond operational downtime. Patients may face risks to medical privacy; the practice itself may face regulatory notification duties, reputational strain and the cost of containment and recovery. Public information does not establish how the practice’s specific defences performed or whether any particular control failed; those questions remain outside the disclosed record.
The information in question
The facts state that internal files were exfiltrated in a ransomware attack. The threat actor further claimed to hold roughly 60 GB of “confidential and personal” material. No itemised inventory of data types—such as clinical notes, insurance identifiers, Social Security numbers, financial account details or employee records—has been published in the available summary. Exact contents are therefore unconfirmed.
In general, cardiology and similar specialty practices commonly store patient demographics, medical histories, procedure reports, insurance and billing data, and internal correspondence. Whether any or all of those categories were present in the material noescape claimed to possess cannot be verified from the public facts. Readers should treat the 60 GB figure and the “confidential and personal” characterisation as the group’s assertions pending any later official disclosure.
The real-world impact
For individuals, the principal risks associated with a medical-practice breach of this kind include potential misuse of personal identifiers for fraud, targeted phishing that references genuine clinical relationships, and unwanted exposure of health-related information. Even when the precise data set is unknown, the combination of identity and medical context can increase the credibility of social-engineering attempts. Credit-monitoring and careful scrutiny of unexpected medical or insurance communications are prudent responses when exposure is possible but unconfirmed.
For the organisation, consequences can include temporary disruption of clinical and administrative systems if encryption occurred as claimed, costs associated with incident response and system restoration, and any notification or regulatory obligations that apply once the scope is better understood. Public detail does not establish the duration of any outage or the financial impact. The absence of a confirmed headcount of affected people also means the full scale of individual notification, if required, remains undetermined.
Were you affected?
If you are a current or former patient, employee or business partner of Mulkay Cardiology Consultants, consider the following practical steps while official confirmation remains limited:
- Monitor financial and insurance statements for unfamiliar activity and place fraud alerts with major credit bureaus if you notice anomalies.
- Treat unsolicited calls, emails or texts that reference the practice or your medical care with caution; verify through known official channels before sharing information or clicking links.
- Review any breach notification you may later receive from the practice for specific guidance on the data involved and recommended protective measures.
- Change passwords on accounts that reused credentials associated with the practice and enable multi-factor authentication where available.
You can also run a free exposure scan of your email address to check whether it has already appeared in known breach data sets. That check does not confirm or rule out involvement in this specific incident, but it can surface other exposures that warrant attention. Stay alert to any formal notices from Mulkay Cardiology Consultants as further verified information becomes available.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
PruittHealth Listed by noescape Ransomware GroupAction Santé Travail Listed by noescape Ransomware GroupCarespring Listed by noescape Ransomware GroupSoutheastern Orthopaedic Specialists Listed by noescape Ransomware GroupLatest breaches
Publicly posted by noescape — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.