newhorizonsmedical.org Listed by lockbit3 Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The newhorizonsmedical.org Listed by lockbit3 Ransomware Group (reported June 7, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
On June 07, 2023, the organisation behind newhorizonsmedical.org was listed by the ransomware group known as lockbit3. Public reporting indicates that internal files were exfiltrated in a ransomware attack. The number of people affected remains unknown, and fuller technical details of the incident have not been disclosed in available records.
New Horizons Medical focuses on treatment for substance use disorders and psychiatric diagnoses. Any unauthorised access to internal material from a provider in this field raises clear concerns for patients and staff, even while the precise scope of what was taken stays limited in public accounts.
Breaking down the breach
According to the available record, newhorizonsmedical.org appeared on a lockbit3 listing dated June 07, 2023. The report states that internal files were exfiltrated in a ransomware attack. No confirmed figure for individuals affected has been released, and public detail does not describe the initial access method, the duration of any intrusion, whether systems were encrypted, or whether a ransom demand was issued or paid.
The listing itself constitutes a claim by the group rather than an independently verified confirmation of every asserted detail. Beyond the statement that internal files were taken, the volume of data, specific file categories, and any subsequent publication or sale of material are not detailed in the facts at hand. Organisations facing such claims typically conduct internal investigations and engage incident-response support; outcomes of those steps, if any, are not part of the public summary provided here.
Inside lockbit3
Lockbit3 is a well-documented ransomware operation that has appeared in numerous public incident reports over recent years. Groups operating under the LockBit name have commonly used a ransomware-as-a-service model, in which affiliates gain access to networks, exfiltrate data, and deploy encryption tools, after which the core operation may publish victim names on a leak site to increase pressure. Typical tactics observed across the broader campaign include exploitation of exposed remote services, stolen credentials, and lateral movement inside networks before data theft and encryption.
Public reporting on LockBit activity has described double-extortion practices: threatening to release stolen data if a ransom is not paid, alongside the encryption of systems. The group has been linked to attacks across many sectors, including healthcare and professional services. In this case, the facts state only that newhorizonsmedical.org was listed and that internal files were exfiltrated; no further specific claims by lockbit3 about this victim—such as sample files, deadlines, or ransom amounts—are included in the given record. Those elements should therefore be treated as unverified beyond the listing itself.
newhorizonsmedical.org and its sector
New Horizons Medical describes its mission as providing patients with compassionate, comprehensive, and evidence-based treatments for substance use disorders and psychiatric diagnoses, with each patient treated as an individual. Organisations of this kind operate in the behavioural-health and addiction-treatment sector. They typically maintain clinical records, appointment and billing information, communications with patients and referral partners, and internal administrative files.
Healthcare and behavioural-health providers are frequent targets for ransomware actors because the data they hold is sensitive and because disruption of care can create urgent operational pressure. A breach affecting such an organisation is consequential not only for continuity of services but also because of the highly personal nature of substance-use and psychiatric information. Even when the exact contents of stolen files remain unconfirmed, the sector context explains why listings of this type draw attention from patients, regulators, and security observers.
What data was at risk
The facts name the exposed material as internal files exfiltrated in a ransomware attack. No further breakdown—such as patient records, financial data, employee information, or specific document types—is provided. The number of people affected is listed as unknown.
Providers that treat substance use disorders and psychiatric conditions ordinarily hold clinical notes, diagnostic information, treatment plans, insurance and billing details, contact data, and internal operational documents. It is reasonable to expect that some combination of these categories could exist within “internal files,” yet the exact contents taken in this incident are unconfirmed. Readers should not assume any particular data element was or was not included; only the broad description of internal-file exfiltration is stated in the record.
Why it matters
For individuals who have received care or otherwise interacted with the organisation, the primary risk is exposure of sensitive personal and health-related information. Substance-use and psychiatric data can carry lasting privacy and stigma consequences if it appears in unauthorised hands. Possible outcomes include targeted phishing, identity misuse, or unwanted disclosure of treatment history. Because the scale of the incident is unknown, it is not possible to say how many people face elevated risk.
For the organisation, a ransomware event that includes data exfiltration can mean operational disruption, regulatory notification duties, potential legal exposure, and the cost of investigation and remediation. Trust between patients and a behavioural-health provider depends heavily on confidentiality; any confirmed or claimed compromise of internal files can affect that trust even when full details remain limited. These are concrete operational and personal impacts, not speculative catastrophe.
If your data was in this claimed breach
If you have been a patient, employee, or partner of New Horizons Medical, treat the possibility of exposure seriously while recognising that public confirmation of individual records is absent. Monitor financial and insurance statements for unfamiliar activity, be cautious of unexpected messages that reference treatment or personal details, and consider placing fraud alerts with major credit bureaus if you believe sensitive identifiers may have been involved. You may also wish to request information directly from the organisation about any notifications it has issued.
As a practical additional step, you can run a free exposure scan of your email address to check whether your information has already surfaced in known breach data sets. Remaining attentive to official updates from the organisation and from relevant regulators is the most reliable way to learn whether further Reported Details emerge.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
sbhc.us Listed by lockbit3 Ransomware Groupco.pickens.sc.us Listed by dispossessor Ransomware Groupphillipsglobal.us Listed by dispossessor Ransomware Grouponyourmark.org Listed by lockbit3 Ransomware GroupLatest breaches
Publicly posted by lockbit — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.