LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Radiosurgery New York Listed by medusa Ransomware Group

HIGH severityUnverified claimHow we verify

Radiosurgery New York Listed by medusa Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·June 4, 2024
Radiosurgery New York Listed by medusa Ransomware Group

Reported June 4, 2024.

HIGH
Severity
June 4, 2024
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The Radiosurgery New York Listed by medusa Ransomware Group (reported June 4, 2024) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Healthcare providers remain a frequent target for ransomware operators, who exploit the sector’s reliance on continuous access to patient records and clinical systems. In this environment, even smaller specialist practices can appear on leak sites, turning routine operations into a public data-exposure event. On 4 June 2024, Radiosurgery New York was listed by the Medusa ransomware group, which claimed to have exfiltrated 64.7 GB of internal files.

The number of people affected has not been disclosed, and public detail remains limited to the group’s own claim. For patients, staff and partners of a radiosurgery centre, the listing raises immediate questions about what material may now be in criminal hands and what practical steps can reduce further harm.

What happened

According to the available record, Radiosurgery New York was listed by the Medusa ransomware group on 4 June 2024. The group asserted that it had carried out a ransomware attack and exfiltrated internal files totalling 64.7 GB. No independent confirmation of the intrusion method, the precise date of the attack, or the full scope of systems involved has been made public. The number of individuals whose data may have been involved is listed as unknown. The organisation itself has not issued a detailed public statement that expands on these claims in the materials reviewed for this report.

Inside medusa

Medusa is a ransomware operation that has been active for several years and is widely documented as employing a double-extortion model. After gaining access to a network, operators typically encrypt systems and simultaneously copy data; if the victim does not pay, the group posts samples or full archives on a dedicated leak site. The group has previously claimed responsibility for attacks against organisations across healthcare, education, manufacturing and professional services. Its listings are public assertions rather than verified forensic findings; in this case the listing of Radiosurgery New York should be treated as the group’s claim that 64.7 GB of internal files were taken. Medusa has not, in the public record associated with this incident, released further technical indicators or a detailed victim-specific manifesto beyond the volume figure and the organisation’s name.

Who is Radiosurgery New York?

Radiosurgery New York describes itself as one of the leading centres for radiation and radiosurgery worldwide. Its corporate office is located at 1384 Broadway at 38th Street, New York City, New York 10018, and the organisation is reported to employ seven people. Radiosurgery practices deliver highly specialised treatment for tumours and other conditions using focused radiation beams; they therefore maintain clinical records, imaging studies, treatment plans, billing information and correspondence with referring physicians and hospitals. Even a small headcount does not reduce the sensitivity of the data such a centre routinely holds. A breach at this type of facility can affect patients who may never have visited the physical office yet whose records were shared for consultation or co-management.

What was likely exposed

The only data category named in the public record is “internal files” said to have been exfiltrated in a ransomware attack, with a claimed volume of 64.7 GB. Exact file types, patient identifiers or other categories have not been disclosed. Organisations of this kind typically store electronic health records, diagnostic images, radiation-treatment parameters, insurance and billing data, employee records and internal administrative documents. Because the precise contents remain unconfirmed, it is not possible to state which of these categories, if any, were among the 64.7 GB. Readers should treat any specific claim about patient names, Social Security numbers or clinical details as unverified until the organisation or a competent authority provides further information.

What's at stake

For individuals, the principal risks are identity theft, medical-identity fraud and unwanted contact if personal or clinical details surface. Stolen health data can be used to open fraudulent insurance claims or to craft convincing phishing messages that reference real treatment history. For the organisation, the consequences include operational disruption, potential regulatory scrutiny under health-privacy rules, reputational damage and the cost of forensic investigation and notification. Because the number of affected people is unknown, the scale of any notification obligation cannot yet be quantified. The 64.7 GB figure, if accurate, is large enough to contain substantial volumes of structured and unstructured records, yet without an inventory it is impossible to assess residual risk precisely.

If your data was in this claimed breach

If you have been a patient, employee or business partner of Radiosurgery New York, treat the listing as a prompt to take basic protective steps. Monitor bank and insurance statements for unfamiliar activity, place a fraud alert with the major credit bureaus if you believe financial identifiers may have been involved, and be sceptical of unsolicited calls or emails that reference your medical history. Change passwords on any accounts that reused credentials associated with the practice, and enable multi-factor authentication wherever it is offered. You can also run a free exposure scan of your email address to check whether that address has already appeared in other known breach data sets; such a scan will not confirm or deny inclusion in this specific incident, but it can highlight additional exposures that warrant attention. Continue to watch for any official notification from the organisation itself, which remains the authoritative source for Reported Details.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyRadiosurgery New York security record
88/100
DoxxScan™ · Low doxx risk
B 83Good record

1 reported incident on record.

See Radiosurgery New York’s full breach history →

More recent breaches

United Sleep Diagnostics Listed by medusa Ransomware GroupNovember 1, 2024American Medical Billing Listed by medusa Ransomware GroupOctober 22, 2024Hospital Episcopal San Lucas Listed by medusa Ransomware GroupSeptember 4, 2024H&H Group Listed by medusa Ransomware GroupJuly 16, 2024

Latest breaches

Read GalaxyWarden’s full analysis of the Radiosurgery New York Listed by medusa Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by medusa — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram