Medusa gang demanded $2m from UK healthcare provider HCRG Care Group

Organization
HCRG Care Group
Exploit
Ransomware
Industry
Healthcare

HCRG Care Group, a private UK provider of community health and social care services formerly known as Virgin Care, was named on the Medusa ransomware group's leak site in February 2025. The company delivers services for the NHS and local authorities, employs around 5,000 people and reports annual turnover of roughly 250 million pounds.

Medusa claimed to have stolen 2.275 terabytes of data and demanded $2 million, offering either to delete its copy or to sell the material to a buyer for the same sum. The gang set a deadline of 27 February 2025 and advertised the option to postpone publication for $10,000 a day. It posted a sample running to about 35 pages that included passport and driving licence scans, staff rotas, a birth certificate and background check records.

HCRG said it was investigating an IT security incident and that its team had observed no suspicious activity since immediate containment measures were applied. The company said services were continuing to operate and that patient care had not been affected. Medusa appeared to have skipped file encryption in favour of data theft and extortion, which is consistent with the provider staying operational.

As of the reporting date HCRG had not confirmed the volume of data taken, had not said how many patients or staff were involved, and had not indicated whether it would negotiate. The Register noted the listing made HCRG Medusa's second UK victim of the year, after Gateshead Council.

Sources