Ransomware victim disclosure
← All victimsDownriver Medical Associates
Claimed by thegentlemen · listed 6 hours ago
Status timeline
- Listed
Jun 4, 2026
- Data leaked
At a glance
- Group
- thegentlemen
- Status
- Data leaked
- Country
- US
- Sector
- Healthcare
- Listed on leak site
- Jun 4, 2026
About the victim
AI dossier — public-source company profileDownriver Medical Associates is a full-service medical office and urgent care center in Wyandotte, Michigan, specializing in internal medicine and family practice. The clinic provides comprehensive primary care for patients of all ages, with an emphasis on wellness, disease prevention, and quality of life.
- Industry
- Healthcare - Primary Care & Urgent Care
- Address
- 2300 Biddle Avenue, Suite 100, Wyandotte, MI 48192
Attack summary
Severity: high — Healthcare provider with confirmed data publication status; likely contains PII and protected health information (PHI) affecting patients, which constitutes regulated sensitive data requiring breach notification under HIPAA.The group claims to have accessed Downriver Medical Associates' systems and published data, though the specific scope of exfiltration and data types are not detailed in the available leak post excerpt.
Data the group says was taken
AI dossier — extracted from the leak post- patient records
- medical information
- personal health data
What the group claims
***.com ***.com/c/downriver-medical-associates/357511215 Downriver Medical Associates is a full-service medical office and urgent care center located in Wyandotte, Michigan. Specializing in internal medicine and family practice, they provide comprehensive primary care for patients of all ages. The clinic focuses on holistic healthcare, emphasizing wellness, disease prevention, and improving the overall quality of life for the local community
Sources
- Victim sitedownrivermedicalassociates.com
Source
Indexed 6 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.
