SYS::ONLINE
Wasteland.
Briefs1691
Issues22
SinceFeb 2026
LIVE
█ Ransomware RADIA-INC-RANSOMWA 2026-08-04

Radia Inc.: Chaos Ransomware Claims 655GB of Patient Records

"Radia Inc., P.S., one of the largest physician-owned radiology groups in the United States, has been named on the Chaos ransomware group's dark web leak site, with the actors claiming to have exfiltrated 655 gigabytes…"

Radia Inc., P.S., one of the largest physician-owned radiology groups in the United States, has been named on the Chaos ransomware group's dark web leak site, with the actors claiming to have exfiltrated 655 gigabytes of patient and corporate data from the practice's networks. One important caveat up front: despite widespread coverage framing this as a confirmed breach, none of the available sources contain a statement from Radia itself, a regulator filing, or a HHS Office for Civil Rights portal entry. Schubert Jonckheer & Kolbe LLP stated on August 3 that "Radia has not confirmed the data breach or reported it to state attorney general offices," a position echoed by Investors Hangout. Every substantive detail below traces back to the threat actor's own claims and to law firm investigations built on those claims. Treat the incident as credible and serious, but attacker-attested rather than victim-confirmed.

What Happened

The consensus timeline across the sources places the leak site posting on July 16, 2026, when a group identifying itself as Chaos (styled CHAOS in several writeups) listed Radia Inc., P.S. on a Tor-hosted extortion site and claimed responsibility for a ransomware attack. ClaimDepot, ClassAction.org, Shamis & Gentile, and Schubert Jonckheer & Kolbe all converge on that date. ClassAction.org adds that the listing surfaced publicly via the cybersecurity monitoring platform DeXpose.io, and that Chaos claimed to have already posted a sample of the exfiltrated data, a standard proof-of-life step in double-extortion operations.

Accounts differ on the date. The Tech Edvocate reports the claim was made on August 3, 2026, roughly three weeks later than every other source. The most likely explanation is that August 3 is when the story reached general tech media, not when the listing appeared; the July 16 date is corroborated by four independent writeups and should be treated as the operative one.

The victim organization is substantial. Radia is a Washington-based, physician-owned radiology group with more than 200 board-certified radiologists. Source descriptions of its footprint vary slightly: Schubert Jonckheer & Kolbe describes "over 50 clinics in Washington and Idaho," while ClassAction.org and Shamis & Gentile describe "over 50 hospitals and specialty clinic partners" plus several outpatient imaging centers across the same two states.

What Was Taken

The single volume figure appearing in every source is 655 GB, and it originates from Chaos, not from any forensic accounting. No source has independently verified the archive size, and none of the eight sources provides a count of affected individuals. Schubert Jonckheer & Kolbe states plainly that "the number of individuals affected is currently unknown." Any headline number circulating beyond that is not supported by this source set.

The data categories, as enumerated by Schubert Jonckheer & Kolbe and largely mirrored by Shamis & Gentile, span both clinical and corporate material:

That combination is worth dwelling on. This is not a stolen email archive or a billing spreadsheet. Diagnostic imaging reports and patient history questionnaires are narrative clinical documents: they describe findings, differential diagnoses and treatment direction in plain language. Bundled with SSNs and dates of birth, they support both financial identity theft and targeted extortion against individual patients, a pattern already seen in attacks on psychotherapy and oncology providers. The Tech Edvocate characterizes the alleged haul as PII, PHI, corporate documents and employee data together, which matches the itemized lists.

Why It Matters

Radiology groups occupy an unusually exposed position in healthcare IT. They are typically independent physician corporations rather than hospital departments, but they hold interface-level connectivity into dozens of separate hospital and clinic environments through PACS, VNA, DICOM and HL7 links. A group serving 50-plus partner sites is, functionally, a hub with many spokes. Compromise of the hub yields imaging and report data originating from every spoke, without the attacker ever touching those partner networks. That concentration is what makes a mid-size practice a high-value target disproportionate to its headcount.

The disclosure gap is the second signal for defenders. Roughly three weeks elapsed between the leak site posting and any public acknowledgement, and as of the most recent sources there is still no confirmation, no regulator notification described, and no notification letters reported. Schubert Jonckheer & Kolbe argues that silence "may have violated federal or state laws," referring to HIPAA breach notification timelines and Washington and Idaho state statutes. Whether or not that legal theory holds, the operational reality for patients is that the plaintiffs' bar reached them before the covered entity did. At least three firms, Schubert Jonckheer & Kolbe, Shamis & Gentile, and attorneys working with ClassAction.org, opened investigations within weeks.

Context matters too. Morgan & Morgan's weekly breach roundup for the week of July 27 catalogues a steady run of healthcare incidents in the same period, including Saint Pete MRI, Madera Community Hospital, BAYADA Home Health Care and ZenPatient, with near-identical exposed-data profiles of names, SSNs, dates of birth and medical information. Radia is not an outlier event; it is one entry in a sustained campaign against imaging, home health and outpatient providers.

The Attack Technique

Here the sourcing thins to almost nothing. No source describes an initial access vector, a ransomware variant hash, encryption behavior, dwell time, or any indicators of compromise. ClassAction.org relays the DeXpose.io description that Chaos claimed to have "gained access to the internal network housing sensitive data on the radiology group's website," a phrasing loose enough that it could describe anything from an internet-facing application compromise to lateral movement from a phished credential. It should not be read as a technical finding.

What can be said about the tradecraft is structural. The observable pattern is textbook double extortion: bulk exfiltration first, leak site listing with a claimed volume figure, and a published data sample to establish proof and pressure. The absence of any reported clinical downtime or imaging service disruption in these sources may suggest exfiltration-weighted extortion rather than a heavy encryption event, but that is inference, not reporting. Note also that "Chaos" is a crowded name in ransomware, historically attached to a builder toolkit reused by multiple unrelated crews. Without a leak site URL, ransom note or sample, attribution to any specific organized group should stay loose.

What Organizations Should Do

For healthcare providers, and specifically for imaging and diagnostic groups sitting between many partner networks:

  1. Inventory and segment your inter-organizational interfaces. Map every PACS, VNA, DICOM and HL7 connection to partner hospitals and clinics. Each should be segmented, individually authenticated, and monitored as a distinct trust boundary rather than a flat extension of the internal network.
  2. Instrument for exfiltration, not just encryption. The damage here, as claimed, is 655 GB leaving the environment. Deploy egress volume baselining and alerting on large outbound transfers from imaging archives and file shares, and treat anomalous bulk reads of report repositories as a paging-level event.
  3. Harden and continuously test internet-facing assets. Externally reachable portals, VPN concentrators, remote access gateways and web applications tied to internal networks remain the dominant initial access route in this sector. Confirm MFA is enforced everywhere, including service and vendor accounts, and patch edge appliances on an accelerated cycle.
  4. Reduce SSN retention in clinical systems. Social Security numbers in medical record and patient questionnaire systems are what convert a PHI breach into a decade-long identity theft exposure. Tokenize, truncate or purge where regulatory retention does not compel storage.
  5. Rehearse the notification decision, not just the technical response. Pre-draft the HIPAA and state attorney general notification path with counsel and assign a named decision owner. The Radia investigations turn substantially on delay, and the reputational and legal cost of silence is now landing faster than the forensic timeline.
  6. Monitor leak sites for your own name and your partners' names. Radia's listing surfaced publicly through a third-party monitoring platform. Continuous dark web monitoring covering your organization, your affiliated practices and your vendors buys days or weeks of lead time on exactly this scenario.

For patients and employees potentially affected, standard guidance applies pending any official notification: place credit freezes with all three bureaus, review Explanation of Benefits statements for care never received, and treat unsolicited contact referencing your medical history as a probable extortion or phishing attempt.

Sources: A Troubling Forecast: Radia Inc Ransomware Attack Exposes Patient R... | PRIVACY ALERT: Radia, Inc. P.S. Under Investigation for ... | Hackers claim to Radia Inc. as the victim of a ransomware attack ex... | Radia Data Breach? Lawyers Investigating Hackers' Claims | Data Breach Investigation: Radia, Inc. Faces Privacy Concerns Amid... | Radia Data Breach Lawsuit Investigation | Radia Faces Investigation Street's Watching Close - Investors Hangout | The Data Breach Brief: Week of July 27th, 2026