Pureform Radiology Center Listed by everest Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Pureform Radiology Center was listed on September 23, 2024, by the everest ransomware group after internal files were exfiltrated in a ransomware attack. An undisclosed number of people may have been affected; anyone who has received services from the center should review their records and consider placing fraud alerts or credit monitoring.
On September 23, 2024, the ransomware group everest listed Pureform Radiology Center, a Canadian medical imaging provider, on its leak site. The group claims it hacked the organization, exfiltrated internal files including medical records and documents, and identified a zero-day exploit in software belonging to a company that acquired Pureform. The number of people affected remains unknown, and independent confirmation of the claims is not publicly detailed.
For patients and staff connected to Pureform Radiology Center, the listing raises practical questions about what data may have left the network and what steps to take while the full picture is still incomplete.
Inside the incident
Public reporting on the incident rests on everest’s leak-site entry dated September 23, 2024. The group states that it gained access to Pureform Radiology Center in Canada, stole all medical records and internal documents, and discovered what it describes as a zero-day exploit in software used by the company that acquired Pureform. It further claims that Pureform’s president hired a recovery negotiator who, according to the group, proved to be an amateur. No independent verification of the intrusion method, the volume of data taken, or the zero-day claim has been released in the available record. The number of individuals whose information may be involved is listed as unknown. Timing of the alleged intrusion itself is not disclosed beyond the September 23 reporting date of the listing.
Inside everest
Everest is a ransomware operation that follows a double-extortion model common among modern groups: after gaining access to a network, operators typically exfiltrate data before encrypting systems, then threaten to publish the stolen material if a ransom is not paid. The group maintains a public leak site where it posts victim names, sample files, and claims about the data taken. Listings of this kind are assertions by the actors themselves and do not automatically confirm that every detail is accurate or that the data has been widely distributed. Everest has previously targeted organizations across multiple sectors, using the pressure of public exposure to force negotiations. In this case the group’s statements about Pureform Radiology Center—including the alleged zero-day find and the characterization of a recovery negotiator—remain unverified claims rather than established facts.
About Pureform Radiology Center
Pureform Radiology Center operates in the medical imaging sector in Canada, providing diagnostic radiology services such as X-rays, CT scans, MRI, and related examinations. Organizations of this type routinely handle sensitive patient information, including personal identifiers, medical histories, imaging studies, referral notes, and billing records. They also maintain internal operational documents, staff records, and vendor contracts. A breach involving a radiology provider is consequential because medical data is both highly personal and long-lived; it can be used for identity fraud, insurance abuse, or targeted social engineering long after the initial incident. The acquisition of Pureform by another company, referenced in the group’s claims, adds a layer of complexity, as parent or successor entities may hold additional systems or data repositories that could be affected.
The information in question
The available facts state that internal files were exfiltrated in a ransomware attack and that everest claims all medical records and internal documents were stolen. Exact data types beyond that description, file counts, or confirmation that every record was taken have not been independently disclosed. Radiology centers typically store patient names, dates of birth, contact details, health-card or insurance numbers, clinical notes, diagnostic images, and appointment histories. Internal files can include employee information, financial records, and system documentation. Because the precise contents remain unconfirmed, it is not possible to state with certainty which specific fields or individuals are involved. The group’s additional claim of discovering a zero-day exploit in the acquirer’s software is likewise presented only as an assertion by everest.
What's at stake
For individuals whose records may have been taken, the primary risks are identity theft, medical fraud, and phishing that leverages accurate personal or clinical details. Stolen health information can be used to open fraudulent accounts, submit false insurance claims, or craft convincing social-engineering messages. Because medical data does not expire the way a password does, the exposure window can last years. For Pureform Radiology Center and any acquiring entity, the stakes include regulatory scrutiny under Canadian privacy law, potential notification obligations, reputational harm, and the operational cost of investigation and remediation. The alleged presence of a zero-day exploit, if accurate, could also affect other organizations running the same software, though that claim has not been corroborated in public reporting.
What to do if you're exposed
If you have been a patient or employee of Pureform Radiology Center, treat the listing as a signal to take basic protective steps while waiting for any official notification. Practical first actions include:
- Monitor bank, credit-card, and insurance statements for unfamiliar activity and consider a credit freeze or fraud alert with Canadian credit bureaus.
- Be alert to unsolicited calls, emails, or texts that reference medical appointments or personal details; verify any request through official channels before responding.
- Change passwords on accounts that may have reused credentials linked to the center, and enable multi-factor authentication where available.
- Request a copy of your medical records or an accounting of disclosures if you wish to understand what information the center holds about you.
- Run a free exposure scan of your email address to check whether your information has already appeared in known breach data sets.
Official guidance from Pureform Radiology Center or Canadian privacy authorities, if issued, should take precedence. Until more verified detail emerges, these measures reduce the most common forms of follow-on harm without relying on unconfirmed claims.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Genie Healthcare Listed by everest Ransomware GroupTotal Patient Care LLC;A Sensitive Touch Home Health;Alphastar Home Health Care;Heart of T Listed by everest Ransomware GroupArtistic Family Dental;Value Dental Center;Sparkling Smiles Family Dentistry Listed by everest Ransomware GroupMyhealthcarebilling Listed by everest Ransomware GroupLatest breaches
Publicly posted by everest — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.