Mediclinic Group listed by the Everest ransomware group
Mediclinic Group
Overview
The Everest ransomware group has listed Mediclinic Group, a private hospital group based in South Africa with operations in Southern Africa, Switzerland and the UAE, on its leak site. Established in 1983, the group operates hospitals across its markets. The listing appeared on 26 May 2025. At the time of analysis, the group's leak page was not reachable.
What was published
The group claims to have exfiltrated data from the hospital group. The archive is expected to include patient records, medical documentation and corporate information.
Risks for affected individuals
- Patient medical data may be exposed.
- Healthcare records are sensitive and could be used for fraud.
- Employees' personal information may be included.
What remains unknown
- The volume of data exfiltrated.
- The exact contents of the leak.
- Whether the data has been published elsewhere.
What affected people should do
Patients should monitor for unusual activity and be cautious of unsolicited communications referencing the group. Mediclinic should notify affected patients and authorities, review its systems, and follow data protection requirements for medical data breaches.
Sources
- http://ransomocmou6mnbquqz44ewosbkjk3o5qjsl3orawojexfook2j7esad.onion/news/Mediclinic_Group