Primeimaging database for sale Listed by everest Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The Primeimaging database for sale Listed by everest Ransomware Group (reported February 1, 2024) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
On 1 February 2024, the ransomware group everest listed what it described as a Primeimaging database for sale on its leak site. The group claimed to have exfiltrated 1.8 terabytes of internal company data and offered it for $20,000. Public detail remains limited: the number of people affected is unknown, and independent confirmation of the breach has not been established beyond the listing itself.
The claim matters because the data types named include personal medical records and oncology results alongside client and employee personal information. For anyone whose records may have been held by a medical imaging provider, the potential exposure of health and identity data carries lasting practical consequences even while the full scope stays unconfirmed.
What happened
According to the everest listing dated 1 February 2024, the group asserted that it had conducted a ransomware attack against Primeimaging and exfiltrated 1.8 terabytes of company internal data. The listing advertised the material for sale at a price of $20,000 and referenced the domain primeimaging.com. The data types the group named as exposed were internal files that it said included personal medical records, oncology results, clients’ and employees’ personal data, passports and other documents.
No further technical details—such as the initial access method, the precise date of intrusion, or whether encryption was deployed—have been publicly disclosed. The number of individuals whose information may be involved is listed as unknown. The listing itself constitutes an unverified claim by the group; no independent verification of the volume, contents or authenticity of the material has been reported in the available facts.
The group behind it: everest
Everest is a ransomware operation that has been active for several years and is known for double-extortion tactics. In common with many such groups, it typically gains access to a network, exfiltrates data, and then threatens to publish or sell the material if a ransom is not paid. The group maintains a dedicated leak site on which it posts victim names, sample files and sale advertisements when negotiations stall or fail.
Public reporting on everest has documented prior listings of corporate and healthcare-related organisations, often accompanied by claims of large data volumes and demands denominated in cryptocurrency or fixed dollar amounts. The group’s statements about any specific victim, including the Primeimaging listing, should be treated as claims rather than What's Publicly Reported unless corroborated by the organisation or independent investigators. No additional statements by everest beyond the February 2024 sale notice are recorded in the available facts for this incident.
About Primeimaging database for sale
Primeimaging appears, from the domain cited in the listing, to operate in the medical-imaging sector. Organisations of this type typically provide diagnostic imaging services—such as radiology, CT, MRI or related oncology imaging—to clinics, hospitals and individual patients. They routinely handle highly sensitive health information, including scan results, referral details, patient identifiers and, in oncology contexts, specialised reports.
A breach involving such a provider is consequential because medical imaging data is both personal and clinical. It can reveal diagnoses, treatment histories and demographic information that, once outside controlled systems, may be difficult to contain. The organisation’s internal files would also ordinarily include employee records and client contracts, expanding the potential circle of affected parties beyond patients alone. Public detail on Primeimaging’s exact size, locations or security posture is not supplied in the breach record.
The information in question
The everest listing states that the material offered for sale consists of 1.8 terabytes of company internal data. The group specifically named personal medical records, oncology results, clients’ and employees’ personal data, passports and other documents. These categories are presented solely as the group’s claim; the exact contents, file formats and completeness of the dataset remain unconfirmed by any independent source.
Organisations in the medical-imaging field typically store patient demographics, imaging studies, radiology reports, insurance details, and staff personnel files. Passports or identity documents may appear in employee onboarding or certain international-patient records. Because the facts do not confirm that any particular record was in fact taken or is authentic, it is not possible to state with certainty which of these typical data types are present. The volume figure of 1.8 terabytes and the $20,000 price are likewise taken only from the group’s advertisement.
The real-world impact
If the claimed data are genuine, individuals whose medical or personal records were held by Primeimaging face risks of identity misuse, targeted phishing that references real health details, and long-term privacy loss. Medical information, once circulated, cannot be “reset” in the way a password can; oncology results in particular can be highly sensitive. Employees whose passports or personal data appear could encounter fraud or social-engineering attempts.
For the organisation itself, the listing creates operational, regulatory and reputational pressure. Healthcare providers are subject to data-protection rules that often require notification of affected individuals and authorities once a breach is confirmed. Even while the claim remains unverified, the mere existence of a public sale notice can erode patient trust and prompt inquiries from partners and regulators. The number of people potentially affected is unknown, so the scale of any notification obligation cannot yet be assessed.
Were you affected?
If you have been a patient, client or employee of a medical-imaging service associated with primeimaging.com, treat the listing as a prompt to review your own exposure. Monitor financial and medical accounts for unusual activity, enable multi-factor authentication where available, and be cautious of unsolicited messages that reference health details. Consider placing fraud alerts with credit bureaus if identity documents may have been involved.
You can also run a free exposure scan of your email address to check whether it has already appeared in known breach datasets. Such a scan will not confirm or rule out involvement in this specific incident, but it provides a practical starting point for understanding whether your information is circulating more widely.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Izmocars Listed by everest Ransomware GroupIndicaOnline Listed by everest Ransomware GroupCrimsgroup Data Leak Listed by everest Ransomware GroupCrimsgroup Listed by everest Ransomware GroupLatest breaches
Publicly posted by everest — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.