HCRG Care Group
bd_5e3814b47947412c · schema v1 · pii pii-v1
Full breach record for HCRG Care Group →Press / market disclosure — not a breach-notification filing
A media or market posting that confirms an incident but carries no breach-notification fields, so compliance clocks aren't assessable. The summary below is extracted from the coverage — verify against the source.
Medusa extortion gang demands $2M from UK's HCRG Care Group • The Register. HCRG Care Group: The UK private healthcare group HCRG Care Group was the victim of a cyberattack by the Medusa ransomware gang, which is demanding $2 million in exchange for not disclosing stolen internal data. The gang has already released samples of this data, including passport and driver's license scans, and threatens to make them public if the payment is not made by February 27. HCRG has confirmed the incident and implemented containment measures, but it is likely that it will refuse to pay the ransom. Linked ransomware group: medusa.
J jump to incidentP pin to compareR raw source
Incident timeline — mostly unverified
? — ?
Breach window unknown
Feb 18, 2025
Press report
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Attack → press
—
Compliance clock
Not assessable
Linked disclosures
Why this link?Ransomware claims (1)
- Leak Sitemedusabd_b78374917c0f955b2025-02-18Candidate
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
Source ceiling
- incident type + narrative only (may be machine-translated)
- discovery date
- materiality
- affected count
- data types
- compliance clock
The ✕ fields stay blank until a regulatory filing or victim disclosure lands.
medusa
According to ransomware.live, Medusa is a ransomware-as-a-service operation active since June 2021 that has targeted over 300 victims across critical infrastructure sectors including healthcare, education, legal, and manufacturing using double-extortion, with attacks surging 42% between 2023 and 2024 and a formal CISA advisory issued in early 2025.