Austin Plastic and Reconstructive Surgery
bd_6ce0fc59aa6d927b · schema v1 · pii pii-v1
Full breach record for Austin Plastic and Reconstructive Surgery →2 incidents on fileThreat-actor claim — not a regulatory filing
This row is a claim by the ransomware group Threeam on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Source: Ransomware.live
Post text · scraped from the leak site
Austin Plastic Reconstructive Surgery, led by Board-Certified Plastic Surgeon Dr. Christine Fisher, specializes in breast reconstruction and a variety of cosmetic surgery procedures. The clinic caters to individuals seeking to enhance their beauty
J jump to incidentP pin to compareR raw source
Incident timeline — mostly unverified
? — ?
Breach window unknown
Aug 7, 2025
Claim posted
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Claim → filing
—
Compliance clock
Not assessable
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- Illinois State AGbd_d8a81728c9b94fb72026-03-01 · +206dVerified
- HHS OCRbd_4941b29582b6fe9f2026-03-30 · +235dVerified
- Texas State AGbd_7709f9890cb95fe22026-03-31 · +236dVerified
Filing propagation · 4 filings · 2 states
View merged incident ↗Pattern: first filing Aug 7, last Mar 31 (TX) — a 236-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
Source ceiling
- actor name
- victim claim
- ransom/leak status
- discovery date
- materiality
- notification
- affected count
- confirmed data types
- compliance clock
The ✕ fields stay blank until a regulatory filing or victim disclosure lands.
threeam
According to ransomware.live, A new Ransomware family identified by the name '3AM' or 'ThreeAM' in September 2023. The ransomware operation was observed by the Symantec team, in which a ransomware affiliate attempted to deploy another ransomware, LockBit, on the target network and then switched to 3AM when LockBit was reportedly blocked. > > The ransomware operation, according to the publication on its Tor-based website, has been operating since mid-August 2023, according to the publication from its first victim. Source: https://github.com/crocodyli/ThreatActors-TTPs