← HCRG Care Group

2025 HCRG Care Group — Medusa ransomware; UK patients first notified June 2026

2025 Unknown records affected Share on X

Data compromised

Patient names, dates of birth, addresses, national insurance numbers, phone numbers, and hospital numbers per June 2026 patient letters—no public victim count

Technical writeup

In February 2025 the Medusa ransomware gang claimed responsibility for an attack on UK independent healthcare provider HCRG Care Group, demanding roughly $2 million. HCRG confirmed it had been breached but provided limited detail while seeking a High Court injunction against publication of stolen data. More than 15 months later, BBC reporting June 18, 2026 described the first direct patient notification letters—one Bath patient received notice June 14, 2026 that categories including date of birth, address, national insurance number, phone number, and hospital number were compromised. HCRG attributed the delay to “uncertain details” and stated there was no evidence of misuse at notification time. The ICO was notified in 2025; BreachHistory indexes recordsAffected 0 pending a finalized regulatory victim count.

Root cause

Medusa ransomware gang attack on UK private healthcare provider (February 2025)

References