Active since 2023 · ~580 known victims · RaaS cartel, double extortion · linked to Scattered Spider
Victim organization
VIP Imaging
A U.S. mobile nuclear and cardiac imaging provider in Anaheim, California, listed on the DragonForce ransomware data-leak site, where the actor has published roughly 8.67 GB of data allegedly stolen from the company. Authenticity and scope are unverified.
United StatesVIP Imaging is the largest mobile nuclear imaging company in Southern California, specializing in cardiac PET/CT and SPECT studies for cardiologists. The company is employee-owned and prides itself on having the best technicians and technology in the industry, ensuring high-quality patient care and support for proper billing.
As posted on the leak site · reproduced verbatim · unverified
Appearance on an active leak site indicates the actor has published data it claims to have exfiltrated, so exposure has likely already occurred rather than being a future threat. As a healthcare provider handling cardiac imaging (PET/CT and SPECT), VIP Imaging holds sensitive patient health information, and any authentic exposure would carry risks of medical identity theft, insurance and billing fraud, and serious privacy harm that cannot be undone by changing a password. DragonForce operates a double-extortion, affiliate-driven model, and the data is listed as already published. No data, samples, or actor contact channels are reproduced here, and the authenticity, scope, and contents remain unverified. VIP Imaging has not publicly addressed the claim as of this post.
Dark Web InformerThreat Intelligence