LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Soni Medical Centre Listed by Booba Team Ransomware Group

HIGH severityUnverified claimHow we verify

Soni Medical Centre Listed by Booba Team Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·October 2, 2026
Soni Medical Centre Listed by Booba Team Ransomware Group

Reported October 2, 2026.

HIGH
Severity
October 2, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Soni Medical Centre was listed on October 02, 2026 by the Booba Team ransomware group, which claims to have stolen data from the organisation. Anyone who has received care at the centre should check their email or post for notifications and consider monitoring their accounts for suspicious activity.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

A ransomware group known as Booba Team has listed Soni Medical Centre on its leak site, according to a public posting dated October 02, 2026. The listing is an unverified accusation from the group itself. As of writing, Soni Medical Centre has not publicly confirmed the claim, and no regulator or independent breach index is cited in the available record as having verified the claim.

Public detail is limited. The number of people who might be affected is unknown, and the types of data the group says were involved are not disclosed in the material provided. The listing refers to roughly 5.5 GB of material and associates a website address, www.lakewoodmedical.ca, with language that also references IT services and IT consulting. Those elements remain claims on a leak site, not confirmed findings. For patients, staff, and partners, the practical question is what such a listing does and does not establish, and what cautious steps make sense if personal or clinical information were ever involved.

What is being claimed

Booba Team has listed Soni Medical Centre on its leak site. The reported date for that listing is October 02, 2026. According to the listing-related summary, the group refers to stolen data in the amount of 5.5 GB and points to the website www.lakewoodmedical.ca, with wording that frames the target in IT services and IT consulting terms. The record does not describe how any intrusion supposedly occurred, when it supposedly began or ended, or whether any ransom demand was made or paid.

People affected are recorded as unknown. Data types named as exposed are not disclosed. No file inventory, sample set, or independent confirmation appears in the facts given. In plain terms, the public is looking at an extortion-style publication claim: a named organisation placed on a leak site, a volume figure attached by the claimants, and little else that can be checked from the outside. Soni Medical Centre has not publicly stated the incident as of writing, so the listing should be read as an allegation, not as a settled account of what happened inside any network.

Who is Booba Team?

Booba Team is known in open reporting as a ransomware and data-extortion crew that pressures organisations by threatening to publish material it says it obtained. Like other groups in this category, it has used leak sites to name victims, post deadlines or countdowns, and advertise purported archives in order to increase leverage. Public coverage of such actors typically describes double-extortion patterns: encryption paired with theft claims, or theft claims alone, followed by publication threats if payment is refused.

Well-documented behaviour for groups of this type includes listing companies across many sectors, sometimes recycling or exaggerating older incidents, and using volume figures and screenshots as marketing. None of that general pattern proves that any particular file set from Soni Medical Centre was taken. For this matter, only what the group claims on its listing is on the table: a named listing, a stated data volume of 5.5 GB, and the website reference already noted. Method, dwell time, and exact contents for this case remain undisclosed in the available record.

About Soni Medical Centre

Soni Medical Centre is presented in the listing context as a medical centre. Organisations in outpatient and clinic care typically manage appointments, demographics, insurance or billing details, clinical notes, referrals, and communications with patients and other providers. Even when a practice also maintains a public website or works with IT vendors, the sensitivity of health-related records is why a leak-site claim draws attention: medical identity details and treatment context can be misused for fraud, stigma, or targeted scams if they ever leave controlled systems.

The listing’s reference to www.lakewoodmedical.ca and to IT services language does not, by itself, redefine the organisation’s clinical role or prove which systems were involved. It only shows how the claimants chose to label the entry. A breach claim against a medical provider matters because of the trust patients place in confidentiality and because health data is regulated and hard to “reset” once exposed. That consequence follows from the sector’s normal data holdings, not from any confirmed inventory in this case.

What data was at risk

The facts state that data types named as exposed are not disclosed. The group claims a volume of 5.5 GB; that figure is part of the listing narrative and is not an audited catalogue. It is therefore not possible to state which fields, databases, or document types—if any—were copied.

If files were taken from an organisation in this sector, firms of this kind typically hold combinations of patient contact information, dates of birth, health-card or insurance identifiers, appointment history, clinical correspondence, billing records, and staff or vendor contact data. Some also store scanned forms, referral letters, or images. Those are sector norms, not a description of what Booba Team actually possessed. Exact contents remain unconfirmed, and the listing’s own description should be treated as attacker marketing rather than an inventory.

The real-world impact

For individuals, impact depends entirely on whether personal information was involved and what it contained—facts that are not established here. If clinical or identity data were ever published or sold, risks could include phishing that impersonates the clinic, attempts to open accounts with stolen identifiers, or embarrassment from sensitive health details. If only generic business files were involved, personal harm might be lower; that distinction cannot be drawn from the current record.

For the organisation, a leak-site listing creates reputational pressure, possible notification duties if a real incident is later confirmed, and operational cost even when claims are disputed. Readers should not assume that “5.5 GB” equals a complete patient database, nor that zero harm is guaranteed. The listing establishes that a known extortion group has named Soni Medical Centre and attached a size claim; it does not establish scope, accuracy, or patient-level exposure. People affected remain unknown in the provided facts.

What to do now

Treat the situation as conditional. If you are a patient or staff member and you later receive credible notice from the centre or a regulator, follow that guidance. In the meantime, be wary of unexpected messages that cite a “breach,” demand payment, or push you to open attachments or enter credentials on unfamiliar pages. Prefer contact channels you already trust, such as a number from a prior appointment card or the official site you type yourself.

If you used the same email address with the clinic that you use elsewhere, consider changing passwords on important accounts, enabling multi-factor authentication where available, and monitoring bank and insurance statements for unfamiliar activity. You can also run a free exposure scan of your email to check whether that address has already appeared in known breach datasets unrelated to this claim. None of these steps prove you were included in the Booba Team listing; they reduce everyday fraud risk while public confirmation remains absent and details stay limited.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

SourceLeak-site claim data adapted from RansomLook.io, used under CC BY 4.0.

CompanySoni Medical Centre security record
84/100
DoxxScan™ · Low doxx risk
B- 76Above-average record

1 reported incident on record.

See Soni Medical Centre’s full breach history →
RelatedMore incidents at Soni Medical Centre

More recent breaches

Raleigh Family Medicine Listed by Booba Team Ransomware GroupOctober 2, 2026University of Illinois Chicago Listed by Booba Team Ransomware GroupOctober 2, 2026EdgeEndo® USA Listed by Booba Team Ransomware GroupOctober 2, 2026Associated Gastroenterologists Of Central New York, P.C Listed by Booba Team Ransomware GroupOctober 1, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the Soni Medical Centre Listed by Booba Team Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by boobateam — unverified claim, pending independent verification. Leak-site claim data adapted from RansomLook.io, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram