LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Southern Indiana Radiological Associates Listed by Storm Ransomware Group

HIGH severity claimedUnverified claimHow we verify

Southern Indiana Radiological Associates Listed by Storm Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·August 6, 2026

SourceLeak-site claim data adapted from RansomLook.io, used under CC BY 4.0.

Southern Indiana Radiological Associates Listed by Storm Ransomware Group

Reported August 6, 2026.

HIGH
Severity
August 6, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Southern Indiana Radiological Associates was listed by the Storm ransomware group on August 06, 2026, after internal files were exfiltrated in a ransomware attack. Individuals who may have been affected should check the organization’s notices and take recommended protective steps.

Severity & verification
HIGH severity claimedUnverified claim
Exposes medical data.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Was your email in the Southern Indiana Radiological Associates Listed by Storm Ransomware Group breach?
See every leak tied to your email — not just this one. 15-second check, no card, no account. Details go to your inbox.

Ransomware groups continue to target healthcare and diagnostic providers, treating clinical and administrative systems as high-value sources of pressure and data. In this landscape, even smaller regional practices appear on leak sites with claims of stolen internal files, leaving patients and partners to assess risk with incomplete public information. Southern Indiana Radiological Associates has been named in one such listing attributed to the Storm ransomware group, reported on August 06, 2026.

Public detail remains limited: the number of people affected is unknown, and the only data description available is that internal files were exfiltrated in a ransomware attack. The listing itself is a claim by the group rather than an independently confirmed disclosure. What follows sets out what is known, what is not, and the practical implications for anyone connected to the practice.

Breaking down the breach

According to the available record, Southern Indiana Radiological Associates was listed by the Storm ransomware group on or around August 06, 2026. The report states that internal files were exfiltrated in a ransomware attack. No further technical detail has been made public about how access was obtained, how long any intrusion lasted, whether systems were encrypted, or whether a ransom demand was issued or paid.

The scale of the incident is undisclosed. There is no confirmed figure for the number of individuals whose information may have been involved, nor any public inventory of specific file names, volumes, or systems. In the absence of an official statement from the organisation detailing forensic findings, the leak-site claim stands as an unverified assertion that data left the network. Timing beyond the reported listing date is also unconfirmed.

The group behind it: Storm

Storm is known in public reporting as a ransomware operation that follows the common double-extortion model: encrypting systems where possible while also copying data and threatening to publish it if payment is not made. Like other groups in this category, it has historically used leak sites to name victims and, in some cases, to release samples or larger archives as pressure. Tactics typically associated with such actors include initial access through phishing, exploited vulnerabilities, or compromised remote-access credentials, followed by lateral movement and data staging before encryption or exfiltration.

No public evidence in the present record confirms that Storm published files specifically belonging to Southern Indiana Radiological Associates beyond the act of listing the organisation. Claims made on criminal leak sites should be treated as assertions by the actors themselves until corroborated by the victim organisation, regulators, or independent investigators. Prior activity attributed to Storm in open sources involves a range of sectors; healthcare and professional services have appeared among named targets in the broader ransomware ecosystem, reflecting the value of sensitive records and the operational disruption such attacks can cause.

About Southern Indiana Radiological Associates

Southern Indiana Radiological Associates provides diagnostic imaging services, including CT, MRI, PET scans, and breast imaging procedures. Established in 1964, the practice serves individuals and referring clinicians in Bloomington and the wider Southern Indiana region, with an emphasis on timely reporting—results delivered to healthcare providers within 48 hours—and patient comfort. It has been recognised as a Breast Imaging Center of Excellence.

Organisations of this type sit at the intersection of clinical care and sensitive personal data. They routinely handle referrals, imaging studies, reports, scheduling information, and billing records that link medical findings to identifiable patients. A breach affecting such a practice is consequential because imaging data and associated administrative files can reveal health conditions, support identity-related fraud, or disrupt the flow of diagnostic information that clinicians rely on for treatment decisions. Even when the precise contents of any stolen material remain unconfirmed, the sector’s data profile elevates the potential stakes for patients and partner providers.

What data was at risk

The public facts state only that internal files were exfiltrated in a ransomware attack. No itemised list of data types—such as patient names, dates of birth, Social Security numbers, insurance details, clinical reports, or images—has been disclosed. Exact contents therefore remain unconfirmed.

In general, radiological and diagnostic practices typically maintain electronic health information, appointment and referral records, billing and insurance data, and internal operational documents. Any of these categories could theoretically be present among “internal files,” but it would be inaccurate to assert that specific fields or record sets were exposed in this incident. Until the organisation or a competent authority releases a verified inventory, affected individuals and partners should treat the exposure as possible rather than proven in detail.

The real-world impact

For patients and referring providers, the primary risks are secondary misuse of any personal or clinical information that may have been taken, and temporary disruption to imaging or reporting workflows if systems were affected. Identity theft, targeted phishing that references real medical interactions, or embarrassment from sensitive health details becoming public are concrete concerns when healthcare-adjacent data leaves a controlled environment—even if the precise files here are unknown. The unknown number of people affected means the circle of potential impact cannot yet be sized.

For the organisation, consequences can include regulatory notification duties, forensic and recovery costs, reputational strain with patients and referring physicians, and possible operational downtime. None of these outcomes is established as fact solely by a leak-site listing; they represent the ordinary range of effects observed after ransomware incidents in the medical imaging sector. Because public detail is limited, both the practice and those who use its services are left managing uncertainty until more verified information appears.

What to do if you're exposed

If you have been a patient or have otherwise shared information with Southern Indiana Radiological Associates, begin by monitoring account statements, insurance explanations of benefits, and credit reports for unfamiliar activity. Consider placing a fraud alert or credit freeze with the major consumer reporting agencies if you believe sensitive identifiers could be involved. Be cautious of unsolicited calls or messages that reference imaging appointments or test results; verify any such contact through official channels you already trust. Keep records of any notices you later receive from the practice or from regulators.

You can also run a free exposure scan of your email address to check whether it has already appeared in known breach datasets. That step does not confirm or rule out involvement in this specific incident, but it provides a practical baseline for further vigilance while official details remain limited.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanySouthern Indiana Radiological Associates security record
64/100
DoxxScan™ · Moderate doxx risk
B- 76Above-average record

1 reported incident on record.

See Southern Indiana Radiological Associates’s full breach history →

More recent breaches

OVP Health Listed by Storm Ransomware GroupAugust 6, 2026Pioneer Bank Listed by Storm Ransomware GroupAugust 6, 2026Nelson Manufacturing Listed by Storm Ransomware GroupAugust 6, 2026EvansPetree Listed by Storm Ransomware GroupAugust 6, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the Southern Indiana Radiological Associates Listed by Storm Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by storm — unverified claim, pending independent verification. Leak-site claim data adapted from RansomLook.io, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram