On March 13, 2025, medical imaging provider University Diagnostic Medical Imaging, PC appeared on the leak site of the fog ransomware group after 28.1 GB of internal files were allegedly exfiltrated.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.
What Public Reporting Shows
Public reporting indicates the New York-based radiology practice suffered a ransomware intrusion in which attackers copied 28.1 gigabytes of documents before encrypting systems. The fog group published a sample of the stolen material on its dark-web leak page, listing udmi.net as a victim. No exact patient count has been disclosed, but the breached data consists of internal files that almost certainly contain protected health information given the nature of a diagnostic imaging company. The listing carries the standard extortion timeline used by this actor: pay or face full publication.
Why This Matters for You and Your Family
When a medical provider loses control of internal records, the information exposed often includes names, dates of birth, Social Security numbers, addresses, insurance details, and imaging reports. 28.1 GB of internal files is large enough to hold thousands of patient records. If you or any member of your family has visited University Diagnostic Medical Imaging in recent years, your personal health data may now sit on a criminal server. Once that information reaches underground markets, it can fuel identity theft, insurance fraud, or targeted scams that feel deeply personal because attackers know your medical history.
The Doxxing and Identity-Chain Risk
Health data rarely travels alone. A single leaked email or phone number from this claimed breach can be combined with credential leaks from other services to build a complete profile. Attackers chain these fragments together: an old password from a medical portal, a child’s gaming username tied to the same family email, a home address pulled from an imaging consent form. The result is doxxing that escalates from nuisance calls to harassment, swatting, or financial takeover. Credential leaks like this one cascade into account takeovers across unrelated services, which is why protecting gaming accounts matters just as much as securing medical portals.