> ## Content Index
> Fetch the complete content index at: https://darkwebinformer.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# DragonForce Ransomware Leaks Data Allegedly Stolen from U.S. Healthcare Firm VIP Imaging
- URL: https://darkwebinformer.com/dragonforce-ransomware-leaks-data-allegedly-stolen-from-u-s-healthcare-firm-vip-imaging/
- Published: 2026-06-29T16:51:51.000Z
- Updated: 2026-06-29T16:51:51.000Z
- Author: Dark Web Informer
- Tags: Ransomware

Ransomware // Leak-site intercept 

RW-2026-0628-VIP Unverified 

OPERATION **DRAGONFORCE** RaaS cartel 

Active since 2023 · \~580 known victims · RaaS cartel, double extortion · linked to Scattered Spider

Victim organization

## VIP Imaging

Assessment 

SeverityCritical

ConfidenceHigh

A U.S. mobile nuclear and cardiac imaging provider in Anaheim, California, listed on the **DragonForce** ransomware data-leak site, where the actor has published roughly **8.67 GB** of data allegedly stolen from the company. Authenticity and scope are **unverified**.

00 Data published 

Listed **2026-06-28**Published **2026-06-28**

Telemetry

GroupDragonForce

Country![United States flag](https://flagcdn.com/w40/us.png)United States

SectorHealthcare / Medical imaging

Domainvipimaging.com

Data volume*8.67 GB*

LocationAnaheim, CA

Listed2026-06-28

Status*Published*

Actor note

> VIP Imaging is the largest mobile nuclear imaging company in Southern California, specializing in cardiac PET/CT and SPECT studies for cardiologists. The company is employee-owned and prides itself on having the best technicians and technology in the industry, ensuring high-quality patient care and support for proper billing.
> 
> As posted on the leak site · reproduced verbatim · unverified 

Auction listing

Auction listingOpen

Current price\-- BTC

**06**Days: **13**Hrs: **23**Min: **07**Sec 

Place bid

Preview

[ Redacted Open image ![DragonForce ransomware leak-site listing for VIP Imaging, redacted](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/7982359786239487625987293876598723.png) ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/7982359786239487625987293876598723.png) 

Assessment

Appearance on an active leak site indicates the actor has published data it claims to have exfiltrated, so exposure has likely already occurred rather than being a future threat. As a healthcare provider handling cardiac imaging (PET/CT and SPECT), VIP Imaging holds sensitive patient health information, and any authentic exposure would carry risks of medical identity theft, insurance and billing fraud, and serious privacy harm that cannot be undone by changing a password. DragonForce operates a double-extortion, affiliate-driven model, and the data is listed as already published. No data, samples, or actor contact channels are reproduced here, and the authenticity, scope, and contents remain **unverified**. VIP Imaging has not publicly addressed the claim as of this post.

Want the non-redacted screenshots? **Paid subscribers** get full claim details and unredacted screenshots. Find this alert on the [ransomware feed](https://darkwebinformer.com/ransomware-feed/) after subscribing. [View pricing](https://darkwebinformer.com/pricing) 

[Dark Web Informer](https://darkwebinformer.com/)Threat Intelligence