On January 07, 2024, the dispossessor ransomware group listed lipsg.com on its leak site, claiming that New York Plastic Surgical Group — one of the largest and longest-established plastic surgery practices in the United States — had its internal files exfiltrated during a ransomware attack.
Watch lipsg.com
Get alerted the next time lipsg.com files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about lipsg.com’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Reported Details from the Listing
The dispossessor leak-site entry states that New York Plastic Surgical Group suffered a ransomware incident in which internal files were taken. The primary disclosure does not quantify the number of records affected, does not list specific data types beyond “internal files,” and does not disclose the ransom demand or payment deadline. The listing simply presents the victim’s domain and a sample of allegedly stolen material as proof of compromise. No official breach notification from the practice had appeared on state attorney-general portals or the HHS breach portal at the time the leak site posted the entry.
Why This Matters for You and Your Family
If you or any member of your family has ever been a patient at New York Plastic Surgical Group or any affiliated Long Island Plastic Surgical Group location, your personal health information and related administrative records may now sit in an attacker-controlled archive. Medical details are among the most sensitive categories of data because they can reveal surgeries, cosmetic procedures, mental-health notes, insurance identifiers, and home addresses. Once exposed, this information does not expire; it can be reused for years in fraud schemes, blackmail attempts, or identity theft targeting you or your relatives.
Doxxing and Identity-Chain Risks
Health-care breaches frequently serve as the starting link in larger doxxing chains. An attacker who obtains your name, date of birth, address, and phone number from plastic-surgery records can cross-reference those details with credential leaks from other services. The result is a rapidly expanding profile that can expose social-media accounts, children’s gaming usernames, school records, and financial logins. Public reporting on similar incidents shows that medical data is often packaged and sold on underground forums precisely because it accelerates this identity-chain mapping. Even if the dispossessor listing does not publish every record, the mere confirmation that internal files were taken means the exposure risk is real and ongoing.