Anubis gang lists Caduceus Medical Group on leak site

The Anubis ransomware group listed Caduceus Medical Group on its leak site, claiming data stolen from the healthcare company's headquarters.

MedRisk Staff
By
2 Min Read

The Anubis ransomware group has listed Caduceus Medical Group on its dark web leak site, claiming data stolen from the healthcare company’s headquarters, according to ransomware trackers.

Ransomware.live logged the listing on August 28, describing the claim as “predictable but dangerous data exposed in a healthcare company breach.” RansomLook’s record of the post describes it as a “data breach at a major healthcare franchise headquarters.”

The claim is unconfirmed, and the medical group has not issued a public statement or breach notification. Trackers caution that leak site listings are the group’s own assertions and may overstate what was actually taken.

Anubis has repeatedly targeted healthcare organizations this year. The group claimed a June attack on Brockton Hospital in Massachusetts that disrupted patient care for weeks, and in mid-August listed home care franchisor Interim HealthCare on its leak site.

For medical groups, a listing with no prior notification often means the intrusion predates public awareness, giving organizations time to find and contain the attack before data is posted. Practices should treat the claim as a red flag: review remote desktop and email exposure, check backup integrity, and scan for signs of credential theft, while awaiting official confirmation from the company.

Share This Article