University Diagnostic Medical Imaging, PC (udmi.net) Listed by fog Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
University Diagnostic Medical Imaging, PC (udmi.net) was listed by the fog ransomware group on March 13, 2025, after internal files were exfiltrated in an attack. Individuals who may have been affected should review notices from the organization and consider protective steps such as monitoring accounts and enabling multi-factor authentication.
On March 13, 2025, University Diagnostic Medical Imaging, PC, which operates the website udmi.net, appeared on a listing by the fog ransomware group. The group claims to have conducted a ransomware attack that involved the exfiltration of 28.1 GB of internal files. The number of people affected is unknown, and public detail on the incident remains limited beyond this reported claim.
Such listings matter because medical imaging providers handle sensitive health-related information. Even when exact impacts are unconfirmed, the appearance of an organization on a ransomware group's site raises legitimate questions for patients, staff, and partners about potential exposure of personal and clinical data.
Breaking down the breach
Public reporting indicates that University Diagnostic Medical Imaging, PC was listed by the fog ransomware group on March 13, 2025. According to the available facts, the group asserts that internal files were exfiltrated during a ransomware attack, with a reported volume of 28.1 GB. No further Reported Details have been disclosed regarding the precise timing of the intrusion, the initial access method, the duration of unauthorized access, or any ransom demands. The number of individuals potentially affected is listed as unknown. Beyond the claim of internal file exfiltration and the stated data volume, additional technical or operational specifics of the incident have not been made public.
Ransomware incidents of this type typically involve encryption of systems combined with data theft, followed by threats to publish or sell the stolen material if payment is not made. In this case, the facts establish only the listing itself, the claimed exfiltration of internal files, and the 28.1 GB figure. Whether systems were encrypted, whether a ransom was paid, or whether any data has been released remains undisclosed in the available record.
Inside fog
Fog is a ransomware operation that has been active in recent years and is known for double-extortion tactics. Groups operating under this model encrypt victim systems while also stealing data, then pressure organizations by threatening to leak the material on dedicated sites if their demands are not met. Fog has previously listed victims across multiple sectors, including healthcare and professional services, and typically posts claims of data volumes along with sample files or directories to support its assertions.
The listing of University Diagnostic Medical Imaging, PC should be treated as an unverified claim by the group. Fog's public activity generally follows a pattern of announcing victims after alleged successful intrusions, often without independent confirmation at the time of posting. No statements attributed specifically to fog about this particular organization, beyond the basic listing and the reported 28.1 GB of internal files, appear in the available facts. Established knowledge of the group indicates it focuses on opportunistic targeting and data theft rather than highly customized campaigns, but those general patterns do not confirm any details unique to this incident.
University Diagnostic Medical Imaging, PC (udmi.net) and its sector
University Diagnostic Medical Imaging, PC is a medical imaging practice that provides diagnostic services such as radiology, ultrasound, CT, MRI, and related procedures. Organizations of this type operate in the healthcare sector and routinely manage patient scheduling, imaging results, referral information, and associated administrative records. The website udmi.net serves as its public-facing presence.
Medical imaging providers sit at a sensitive intersection of clinical care and personal data. They typically receive referrals from physicians, store images and reports that form part of a patient's medical history, and maintain billing and contact details. A breach involving such an entity is consequential because the data often qualifies as protected health information under U.S. privacy rules and can include identifiers that link individuals to specific medical conditions or procedures. Even when the full scope of an incident is unconfirmed, the sector's reliance on accurate, confidential records means any unauthorized access carries elevated privacy and operational risks for both patients and the practice itself.
What was likely exposed
The facts state that internal files were exfiltrated in a ransomware attack, with a reported volume of 28.1 GB. No more granular inventory of the specific data types has been disclosed. The number of people affected is unknown.
Organizations that provide diagnostic medical imaging commonly hold patient names, dates of birth, contact information, insurance details, medical record numbers, referral notes, imaging reports, and sometimes scanned identification documents. Administrative files may also include staff records, contracts, and internal correspondence. Because the exact contents of the 28.1 GB claimed by fog have not been independently verified or itemized in public reporting, it is not possible to state with certainty which categories of information were taken. The claim of internal file exfiltration is consistent with the types of material such practices store, yet the precise composition remains unconfirmed.
What's at stake
For individuals whose information may have been involved, the primary risks include identity theft, medical identity fraud, and unwanted contact or phishing attempts that leverage accurate personal or health details. Stolen medical data can be used to submit false insurance claims or to craft convincing social-engineering attacks. Because the number of affected people is unknown and the exact data types are unconfirmed, the scale of these risks cannot yet be quantified.
For the organization, the consequences may include regulatory notification obligations, potential investigations under health-privacy laws, operational disruption from system recovery, and reputational harm that affects patient trust and referral relationships. Recovery from ransomware often requires forensic review, system restoration, and enhanced monitoring, all of which carry costs and divert resources from clinical work. Until more detail emerges, both the human and institutional impacts remain matters of prudent caution rather than established fact.
Were you affected?
If you have been a patient, employee, or business partner of University Diagnostic Medical Imaging, PC, consider taking basic protective steps. Monitor financial and insurance statements for unusual activity, place a fraud alert with credit bureaus if you are concerned about identity misuse, and be alert to unsolicited communications that reference medical appointments or personal details. Change passwords on any accounts that may have reused credentials associated with the practice, and enable multi-factor authentication where available.
Readers can also run a free exposure scan of their email address to check whether their information has already surfaced in known breach data sets. Doing so provides an additional layer of visibility while official notifications, if any, are still pending. Public detail on this incident remains limited, so continued attention to official statements from the organization or relevant authorities is advisable.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Newtown Friends School (newtownfriends.org) Listed by fog Ransomware GroupEl Camino Real Academy (elcaminorealacademy) Listed by fog Ransomware GroupMagnolia Manor (magnoliamanor.com) Listed by fog Ransomware GroupSCOLARO FETTER GRIZANTI & McGOUGH, P.C. (scolaro.com) Listed by fog Ransomware GroupLatest breaches
Publicly posted by fog — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.