HCRG Care Group
Incident posture
Linked entities
- Victim
- HCRG Care Group
- Threat actors
- 1 actor
- Sources
- 1 source
Timeline
Summary
The Medusa ransomware gang claimed responsibility for stealing 2.275 TB of data from the UK-based private health and social services provider formerly known as Virgin Care, demanding $2 million to either delete the information, sell it, or delay its public release for $10,000 per day. Leaked samples allegedly included passport and driving license scans, staff rotas, a birth certificate, and background check data. The organization confirmed it was investigating the IT security incident alongside external forensic specialists and reported no suspicious activity following the implementation of containment measures, with patient services continuing to operate normally. Unlike many ransomware incidents, Medusa opted to skip encryption and rely solely on data theft and extortion, with the deadline for payment set roughly two weeks after the claim surfaced.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On February 12, 2025, The Register reported an ongoing cybersecurity incident involving HCRG Care Group, a private UK health and social services provider formerly known as Virgin Care and currently owned by Twenty20 Capital. HCRG delivers child and family health and social services across the United Kingdom under contracts with the NHS and local authorities, employing a workforce of approximately 5,000 people, with an annual turnover to March 2023 reported at just under £250 million (approximately $315 million). The incident came to public attention through an update posted on a dark-web site operated by the Medusa ransomware gang, also referred to as the Medusa extortion gang. Medusa claimed to have stolen 2.275 terabytes of data from HCRG and issued a ransom demand, offering three options: selling the allegedly stolen information to a buyer for $2 million (approximately £1.6 million), deleting its copy of the data for the same amount, or leaking the full dataset online if no payment was made by a stated deadline of February 27. Additionally, the group stated it would delay the release of the data for $10,000 (approximately £8,000) per day, a mechanism seemingly intended to keep negotiations open.
Medusa had already published samples of the purportedly stolen material, totaling 35 pages, prior to the article's publication. These samples included passport scans, driving license scans, staff rotas, a birth certificate, and data from background checks. The publication of these samples served as proof of the breach and as leverage in the extortion attempt. Notably, the attackers appear to have skipped the encryption phase commonly associated with ransomware operations, opting instead for a pure data theft and extortion model in which the threat to publish sensitive information is the primary pressure tactic. An HCRG spokesperson confirmed to The Register on Wednesday that the organization was investigating an IT security incident and had recently identified a post on the dark web by a group claiming responsibility. The spokesperson added that the organization's team had not observed any suspicious activity since the implementation of immediate containment measures and that external forensic specialists had been engaged to investigate the incident.
HCRG stated that its services were continuing to operate and that patients with appointments or those needing to access services should continue to do so. This continuity of operations stood in contrast to other healthcare-sector ransomware incidents, such as the 2024 attack on University Medical Center in Lubbock, Texas, which forced severe operational limitations and the diversion of ambulances. The HCRG incident was not the first high-profile Medusa attack on a British organization in 2025; in January 2025, the gang claimed a similar data theft and extortion operation against Gateshead Council. Despite Medusa's threats, Gateshead Council refused to pay the $600,000 ransom, after which Medusa published the allegedly stolen data online.
Medusa ransomware first surfaced in late 2022 and primarily targets Windows environments. According to research from Palo Alto Networks' Unit 42, the group concentrates its attacks on five sectors: technology, education, manufacturing, healthcare, and retail. US organizations have been the gang's most frequent victims, followed closely by UK firms. The HCRG breach fits squarely within this pattern, both in sector targeting and in geographic focus. The Register noted it was likely HCRG would also refuse to pay the ransom, and even if payment were made, there would be no guarantee the group would not sell the data regardless. Additional context from security firm Cybereason indicated that 78 percent of organizations that paid a ransom in the previous year were attacked again, with 63 percent of those facing demands for larger payouts in subsequent incidents. HCRG's engagement of external forensic specialists and its public confirmation of containment measures represent the organization's documented response actions at the time of reporting, with further details on the full scope of the intrusion, the method of initial access, and the exact categories of affected data still subject to ongoing investigation as of the article's publication date.
Sources
Sources available to members: 1 source.