LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Pureform Radiology Center Listed by everest Ransomware Group

HIGH severity claimedUnverified claimHow we verify

Pureform Radiology Center Listed by everest Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·September 23, 2024
Pureform Radiology Center Listed by everest Ransomware Group

Reported September 23, 2024.

HIGH
Severity
September 23, 2024
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Pureform Radiology Center was listed on September 23, 2024, by the everest ransomware group after internal files were exfiltrated in a ransomware attack. An undisclosed number of people may have been affected; anyone who has received services from the center should review their records and consider placing fraud alerts or credit monitoring.

Severity & verification
HIGH severity claimedUnverified claim
Exposes medical data.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

On September 23, 2024, the ransomware group everest listed Pureform Radiology Center, a Canadian medical imaging provider, on its leak site. The group claims it hacked the organization, exfiltrated internal files including medical records and documents, and identified a zero-day exploit in software belonging to a company that acquired Pureform. The number of people affected remains unknown, and independent confirmation of the claims is not publicly detailed.

For patients and staff connected to Pureform Radiology Center, the listing raises practical questions about what data may have left the network and what steps to take while the full picture is still incomplete.

Inside the incident

Public reporting on the incident rests on everest’s leak-site entry dated September 23, 2024. The group states that it gained access to Pureform Radiology Center in Canada, stole all medical records and internal documents, and discovered what it describes as a zero-day exploit in software used by the company that acquired Pureform. It further claims that Pureform’s president hired a recovery negotiator who, according to the group, proved to be an amateur. No independent verification of the intrusion method, the volume of data taken, or the zero-day claim has been released in the available record. The number of individuals whose information may be involved is listed as unknown. Timing of the alleged intrusion itself is not disclosed beyond the September 23 reporting date of the listing.

Inside everest

Everest is a ransomware operation that follows a double-extortion model common among modern groups: after gaining access to a network, operators typically exfiltrate data before encrypting systems, then threaten to publish the stolen material if a ransom is not paid. The group maintains a public leak site where it posts victim names, sample files, and claims about the data taken. Listings of this kind are assertions by the actors themselves and do not automatically confirm that every detail is accurate or that the data has been widely distributed. Everest has previously targeted organizations across multiple sectors, using the pressure of public exposure to force negotiations. In this case the group’s statements about Pureform Radiology Center—including the alleged zero-day find and the characterization of a recovery negotiator—remain unverified claims rather than established facts.

About Pureform Radiology Center

Pureform Radiology Center operates in the medical imaging sector in Canada, providing diagnostic radiology services such as X-rays, CT scans, MRI, and related examinations. Organizations of this type routinely handle sensitive patient information, including personal identifiers, medical histories, imaging studies, referral notes, and billing records. They also maintain internal operational documents, staff records, and vendor contracts. A breach involving a radiology provider is consequential because medical data is both highly personal and long-lived; it can be used for identity fraud, insurance abuse, or targeted social engineering long after the initial incident. The acquisition of Pureform by another company, referenced in the group’s claims, adds a layer of complexity, as parent or successor entities may hold additional systems or data repositories that could be affected.

The information in question

The available facts state that internal files were exfiltrated in a ransomware attack and that everest claims all medical records and internal documents were stolen. Exact data types beyond that description, file counts, or confirmation that every record was taken have not been independently disclosed. Radiology centers typically store patient names, dates of birth, contact details, health-card or insurance numbers, clinical notes, diagnostic images, and appointment histories. Internal files can include employee information, financial records, and system documentation. Because the precise contents remain unconfirmed, it is not possible to state with certainty which specific fields or individuals are involved. The group’s additional claim of discovering a zero-day exploit in the acquirer’s software is likewise presented only as an assertion by everest.

What's at stake

For individuals whose records may have been taken, the primary risks are identity theft, medical fraud, and phishing that leverages accurate personal or clinical details. Stolen health information can be used to open fraudulent accounts, submit false insurance claims, or craft convincing social-engineering messages. Because medical data does not expire the way a password does, the exposure window can last years. For Pureform Radiology Center and any acquiring entity, the stakes include regulatory scrutiny under Canadian privacy law, potential notification obligations, reputational harm, and the operational cost of investigation and remediation. The alleged presence of a zero-day exploit, if accurate, could also affect other organizations running the same software, though that claim has not been corroborated in public reporting.

What to do if you're exposed

If you have been a patient or employee of Pureform Radiology Center, treat the listing as a signal to take basic protective steps while waiting for any official notification. Practical first actions include:

Official guidance from Pureform Radiology Center or Canadian privacy authorities, if issued, should take precedence. Until more verified detail emerges, these measures reduce the most common forms of follow-on harm without relying on unconfirmed claims.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyPureform Radiology Center security record
87/100
DoxxScan™ · Low doxx risk
B 80Good record

1 reported incident on record.

See Pureform Radiology Center’s full breach history →

More recent breaches

Genie Healthcare Listed by everest Ransomware GroupDecember 20, 2024Total Patient Care LLC;A Sensitive Touch Home Health;Alphastar Home Health Care;Heart of T Listed by everest Ransomware GroupDecember 17, 2024Artistic Family Dental;Value Dental Center;Sparkling Smiles Family Dentistry Listed by everest Ransomware GroupDecember 17, 2024Myhealthcarebilling Listed by everest Ransomware GroupDecember 13, 2024

Latest breaches

Read GalaxyWarden’s full analysis of the Pureform Radiology Center Listed by everest Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by everest — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram