Medusa ransomware gang demands $2M from UK private health services provider

Exclusive HCRG Care Group, a private health and social services provider, has seemingly fallen victim to the Medusa ransomware gang, which is threatening to leak what’s claimed to be stolen internal records unless a substantial ransom is paid.

Previously known as Virgin Care and now owned by Twenty20 Capital, HCRG runs child and family health and social services across the UK for the NHS and local authorities, with a workforce said to number 5,000. Its annual turnover to March 2023, its latest available figure, was just shy of £250 million ($315 million).

In an update on its dark-web site, the Medusa crew claimed it had stolen 2.275 TB of data from HCRG, and will either sell that information to a buyer for $2 million (£1.6 million), delete its copy of that info for the same amount, or leak it all online if no one pays up by February 27.

Additionally, the gang claims it will delay the release for $10,000 (£8,000) per day, presumably to keep negotiations open. It has already leaked samples, totaling 35 pages, of what’s said to be pilfered information, including passport and driving license scans, staff rotas, a birth certificate, and data from background checks.

Screenshot of Medusa ransomware note for HCRG

Tick-tock … Medusa’s ransom demand on its Tor-hidden site against HCRG Care Group. We’ve redacted a URL to where miscreants can download a list of files in the supposedly swiped data

“We can confirm that we are currently investigating an IT security incident and have recently identified a post on the dark web by a group claiming responsibility,” a spokesperson for HCRG told The Register Wednesday.

“Our team has not observed any suspicious activity since the implementation of immediate containment measures, and we are working with external forensic specialists to investigate the incident. Our services are continuing to operate and safely see patients, and those with appointments or who need to access our services should continue to do so.”

For now, then, HCRG is still operational – a stark contrast to what happened in Texas last year, when the University Medical Center in Lubbock was forced to severely limit operations and turn away ambulances following a ransomware attack.

Medusa surfaced in late 2022, primarily targeting Windows environments. According to Palo Alto Networks’ Unit 42, it mainly targets five sectors: Technology, education, manufacturing, healthcare, and retail. US organizations are the gang’s top victims, with UK firms following closely behind.

The HCRG incident marks the second high-profile attack from Medusa this year against a British organization. Last month, it claimed it had pulled a similar heist against Gateshead Council. Despite the gang’s threats, the council refused to pay the $600,000 ransom, leading Medusa to publish what’s said to be stolen data online.

It’s likely HCRG will refuse to play ball, too. And even if the healthcare group did pay, there’s no guarantee Medusa wouldn’t double-dip by selling the data anyway. And according to security shop Cybereason, last year 78 percent of organizations that paid a ransom were attacked again, with 63 percent facing demands for an even larger payout the second time around. ®

Read More

Latest

Tencent Music Posts 7.3% Q1 2026 Revenue Jump, Points to Triple-Digit Live Growth and Continued Superfan Expansion

A live performance from Jay Chou, whose Children of the Sun is said to have generated about $14.7 million on Tencent Music during Q1 2026. Photo Credit: GEM_Ady Amid a continued SVIP expansion and a triple-digit revenue boost on the concerts side, Tencent Music Entertainment (TME) has reported nearly $1.2 billion in Q1 2026 revenue.

Newsletter

Don't miss

Tencent Music Posts 7.3% Q1 2026 Revenue Jump, Points to Triple-Digit Live Growth and Continued Superfan Expansion

A live performance from Jay Chou, whose Children of the Sun is said to have generated about $14.7 million on Tencent Music during Q1 2026. Photo Credit: GEM_Ady Amid a continued SVIP expansion and a triple-digit revenue boost on the concerts side, Tencent Music Entertainment (TME) has reported nearly $1.2 billion in Q1 2026 revenue.

BLXCKIE Previews New Song “Uphi Usomnyama”

MusicBLXCKIE Previews New Song “Uphi Usomnyama.” The SA...

WD sees sustainability as key business driver in an ‘AI economy’

Hard drive company WD promoted long-term operations and sustainability executive Jackie Jung to become its first chief sustainability officer in February, as it steps up sales to companies building AI data centers. Her vision: Turn sustainability into a “brand” for WD, a strategy that reduces risk for the $6 billion company (formerly known as Western

5 Business Ideas Worth Starting in 2026

If there is one thing Nigerians understand well, it is how to spot opportunity inside hardship. In 2026, that mindset will matter more than ever. The economy is tough, competition is rising, and many people are looking for smarter ways to earn, build, and survive. But even in a difficult environment, some businesses still stand

Getting a business loan now comes with a frequent flyer upside

Australian fintech Prospa has partnered with Qantas Business Rewards, letting eligible SMEs earn up to 500,000 points per loan. What’s happening: Australian fintech lender Prospa has partnered with Qantas Business Rewards to allow eligible small and medium business owners to earn up to 500,000 Qantas Points per loan when taking out a Prospa Small Business