The Barracuda extortion gang has posted two US clinical practices on its leak site, one dental and one medical, in listings that expose a sharp difference in how the group monetizes the data.
Skyline Implants and Periodontics, a dental implant and gum care practice, was listed August 23 with an 800 GB cache marked free. The gang says the files include patient medical documents, MRI scans in DICOM format, personal photos, and the personal data of the practice’s doctor, along with equipment and pharmaceutical procurement records.
The same day, Clinical Associates of the Finger Lakes, a medical practice in upstate New York, was listed with a 447 GB cache marked selling at $1K. The post says the files include children’s medical records, personal information of parents and employees, and a full dump of the mail server.
Both claims are unconfirmed, and neither practice has publicly acknowledged the incidents. Threat trackers logged the two listings within hours of each other, and GalaxyWarden’s breach index independently confirms both with high severity ratings.
The listings illustrate the two common outcomes for extorted data: immediate public release or a low-priced sale intended to pressure the victim. Dental and small medical practices remain favored targets because they hold years of imaging and records data with comparatively thin security staffing.
For practices in this segment, encrypting email at rest, restricting DICOM access to the imaging network, and maintaining tested offline backups are the defenses most likely to shorten an incident’s blast radius.