On February 1, 2024, French digital-radiology provider DMS Imaging appeared on the leak site operated by the Cuba ransomware group. The listing states that internal files were exfiltrated during a ransomware attack; the exact number of records and the full scope of data remain undisclosed by both the threat actor and the company.
Watch dms-imaging
Get alerted the next time dms-imaging files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about dms-imaging’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Primary Disclosure Details
The Cuba leak portal entry states that DMS Imaging, a company specializing in medical imaging solutions with international operations, suffered a ransomware intrusion. It explicitly lists the victim under the identifier “dms-imaging@cuba” and asserts that sensitive internal files were successfully exfiltrated. The disclosure does not quantify affected records, name specific data types such as patient images or personal health information, or provide a ransom demand figure. As of the publication date, no separate breach notification from DMS Imaging had been located in French CNIL filings or public statements, leaving the precise contents of the stolen archive unknown to outsiders.
Why This Matters for You and Your Family
When a medical-imaging company’s internal files are stolen, the exposure can reach far beyond corporate walls. Radiology practices routinely handle names, dates of birth, medical record numbers, and sometimes full imaging studies tied to identifiable individuals. Even if the Cuba listing does not enumerate these fields, the mere confirmation of exfiltrated internal files creates a realistic risk that your or your family’s protected health information could now sit in an adversary’s hands. Medical data retains high value on underground markets because it combines identity details with sensitive treatment history that cannot be easily changed like a password. A single leak of this nature can fuel years of fraud, insurance abuse, or targeted scams against you and those you care for.
Doxxing and Identity-Chain Risks
Exfiltrated internal files rarely exist in isolation. They often contain employee directories, vendor contracts, email correspondence, and spreadsheets that link names, addresses, phone numbers, and sometimes family-member details. Threat actors routinely cross-reference such material with other breaches to build persistent identity chains. A username discovered in one document can be matched to a reused password from an earlier breach, leading to account takeovers on personal email, banking, or social-media accounts. These chains frequently cascade into full doxxing, where an attacker publishes your home address, relatives’ names, and even children’s information. Because DMS Imaging serves an international clientele, the risk extends to patients and their households whose data may have been stored in the compromised environment.