Ransomware victim disclosure
← All victimsTLC Perinatal PA
listed as TLC Perinatal · Claimed by Genesis · listed 15 hours ago
Status timeline
- ListedOct 1, 2026
- Data leakeddate unknown
At a glance
- Group
- Genesis
- Status
- Data leaked
- Country
- United States
- Sector
- Healthcare
- Listed on leak site
- Oct 1, 2026
About the victim
AI dossier — public-source company profileTLC Perinatal PA is a maternal fetal medicine and perinatal specialty practice with offices in Silver Spring and Germantown, Maryland. Led by perinatologist Richard Broth, MD, the practice offers comprehensive prenatal ultrasounds, high-risk pregnancy management, genetic counseling, and related obstetric services.
- Industry
- Healthcare – Maternal Fetal Medicine & Perinatal Services
- Address
- Silver Spring and Germantown, MD, US
Attack summary
Severity: critical — Confirmed exfiltration of regulated healthcare data at scale (500 GB) including patient personal information, medical records, and financial data. Healthcare provider breach involving PII and sensitive medical information meets critical threshold.The Genesis group claims to have exfiltrated approximately 500 GB of data from TLC Perinatal, including healthcare records, personal data, financial information, user folders, and operational data from the company fileserver.
Data the group says was taken
AI dossier — extracted from the leak post- Healthcare data
- Personal data (patient PII)
- Financial data
- User folders
- Operational data
- Company fileserver contents
What the group claims
A provider of healthcare services.
The leak post
captured from the group's siteA provider of healthcare services. ``` - 500 Gb of accessible data. - Healthcare Data. - Personal Data. - Financial Data. - Users folders. - Operational Data. - Data from company fileserver. ``` [Download The List of Company Files](http://genesis6ixpb5mcy4kudybtw5op2wqlrkocfogbnenz3c647ibqixiad.onion/download/b2fe02bd0fd472458ab5.txt)
Sources
Source
Indexed 15 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

