LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › VirMedice Listed by pear Ransomware Group

HIGH severity claimedUnverified claimHow we verify

VirMedice Listed by pear Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·September 11, 2025
VirMedice Listed by pear Ransomware Group

Reported September 11, 2025.

HIGH
Severity
September 11, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

VirMedice was listed by the pear ransomware group on September 11, 2025, after internal files were exfiltrated in a ransomware attack. The number of people affected has not been disclosed; individuals should check whether their information was exposed and take any recommended protective steps.

Severity & verification
HIGH severity claimedUnverified claim
Exposes medical data.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

People whose personal or medical information may sit inside systems connected to VirMedice now face a concrete question: whether internal files taken in a ransomware incident include records that can be used against them. Public reporting so far is limited, yet the listing of the company by a ransomware group means the possibility of exposure cannot be dismissed. For patients, staff, and partner practices that rely on electronic health-record and practice-management tools, the practical stakes are identity theft, medical fraud, and long-term privacy loss.

On 11 September 2025 VirMedice appeared on a leak site operated by the group known as pear. The available facts state only that internal files were exfiltrated in a ransomware attack; the number of people affected remains unknown and the precise contents of those files have not been confirmed.

What happened

According to the public record, VirMedice was listed by the pear ransomware group on 11 September 2025. The sole description provided is that internal files were allegedly exfiltrated during a ransomware attack. No further technical details—such as the initial access method, the duration of the intrusion, the volume of data taken, or any ransom demand—have been disclosed. The number of individuals whose information may be involved is listed as unknown. Because the listing itself is a claim made by the threat actor, it has not been independently verified in the available facts.

Ransomware incidents of this type typically involve encryption of systems combined with data theft, after which the group threatens to publish the stolen material if payment is not made. In this case the facts stop at the announcement of the listing and the statement that internal files were removed. Timing beyond the report date, scale, and exact method remain undisclosed.

The group behind it: pear

Pear is a ransomware operation that follows the now-common double-extortion model: encrypting a victim’s systems while simultaneously stealing data and threatening to leak it. Like other groups in this category, pear maintains a public leak site where it posts victim names and, in some cases, samples of stolen files to pressure organisations into paying. Public reporting on pear has documented its use of standard ransomware tooling, affiliate-style recruitment, and the practice of listing companies across multiple sectors once data has been exfiltrated.

The group’s listing of VirMedice is therefore a claim that the organisation was successfully compromised and that internal files were taken. No additional statements attributed to pear about this specific victim—such as file counts, screenshots, or ransom amounts—appear in the facts. Established public knowledge of pear’s tactics does not extend to inventing details unique to this incident; the only confirmed public assertion is the listing itself and the description of internal-file exfiltration.

About VirMedice

VirMedice supplies NextGen Ambulatory Electronic Health Records (EHR) and NextGen Ambulatory Practice Management (PM) software, offered in two models. Organisations of this kind sit at the centre of outpatient clinical and administrative workflows. They store or process patient demographics, clinical notes, appointment schedules, billing information, insurance details, and provider credentials. Because the software is used by medical practices, any compromise can reach data belonging to both the software vendor and its customer clinics.

A breach at a healthcare-IT provider is consequential precisely because the data involved is both sensitive and regulated. Electronic health records and practice-management systems routinely contain information protected under medical-privacy rules; unauthorised access can therefore affect patients who never had a direct relationship with VirMedice itself but whose records passed through its platforms or support systems.

What was likely exposed

The facts state only that “internal files” were exfiltrated. No inventory of those files—patient records, employee data, source code, financial documents, or customer lists—has been released. Organisations that develop and support ambulatory EHR and PM software typically hold a mixture of proprietary technical material, customer configuration data, support tickets, and, in some cases, copies or extracts of clinical and billing information necessary for troubleshooting or hosting services.

Because the exact contents remain unconfirmed, it is not possible to assert that any particular category of personal data was taken. What can be said is that the nature of VirMedice’s business makes the presence of health-related and personally identifiable information plausible, yet the public record does not verify which, if any, of those categories were among the internal files removed.

What's at stake

For individuals, the primary risks are identity theft, medical identity fraud, and the permanent loss of privacy over clinical or financial details. Stolen health data can be used to open fraudulent insurance claims, obtain prescription drugs, or craft highly targeted phishing messages. Even if the files contain only internal administrative material, employee or contractor records could still enable credential stuffing or social-engineering attacks against the same people later.

For VirMedice and its customer practices the stakes include regulatory scrutiny, contractual liability to clinics that rely on the software, and the operational cost of investigation and remediation. Trust in electronic health-record systems is fragile; any confirmed exposure of patient data can prompt practices to reassess vendors and can leave patients uncertain whether their records remain confidential. Because the number of affected people is unknown, the full scope of these risks cannot yet be measured.

If your data was in this claimed breach

If you are a patient, employee, or partner whose information may have passed through VirMedice systems, begin by monitoring financial and medical statements for unfamiliar activity. Place fraud alerts with the major credit bureaus and consider a credit freeze if you see signs of misuse. Change passwords on any accounts that may have shared credentials with systems linked to the company, and enable multi-factor authentication wherever it is available. Keep records of any notices you receive from VirMedice or from clinics that use its software.

You can also run a free exposure scan of your email address to check whether that address has already appeared in known breach data sets. Such a scan will not confirm or rule out involvement in this specific incident, but it can show whether your information has surfaced elsewhere and help you prioritise further protective steps. Stay alert for official updates from VirMedice or from healthcare regulators; until more detail is published, treat any unsolicited contact claiming to relate to this breach with caution.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyVirMedice security record
84/100
DoxxScan™ · Low doxx risk
B- 76Above-average record

1 reported incident on record.

See VirMedice’s full breach history →

More recent breaches

Iroquois Memorial Hospital Listed by pear Ransomware GroupNovember 25, 2025Medical Center, LLP Listed by pear Ransomware GroupOctober 17, 2025Western Orthopaedics Listed by pear Ransomware GroupSeptember 30, 2025Brevard Skin Listed by pear Ransomware GroupSeptember 28, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the VirMedice Listed by pear Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by pear — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram