Ransomware victim disclosure
← All victimsCrystal Coast Pain Management Center
listed as crystalcoastpm.com · Claimed by Lockbit5 · listed 4 months ago
Status timeline
- ListedFeb 23, 2026
- Data leakeddate unknown
At a glance
- Group
- Lockbit5
- Status
- Data leaked
- Country
- United States
- Listed on leak site
- Feb 23, 2026
About the victim
AI dossier — public-source company profileCrystal Coast Pain Management Center (CCPM) is a specialty medical practice located in North Carolina, United States, focused on treating patients with acute and chronic pain. The practice offers a comprehensive range of diagnostic and interventional procedures including epidural spinal injections, spinal cord stimulation, radiofrequency ablation, and medication management. CCPM serves more than 24,000 patients per year and requires physician referrals for new patient appointments.
- Industry
- Pain Management & Interventional Medicine
Attack summary
Severity: critical — The victim is a medical practice handling protected health information (PHI) for over 24,000 patients annually. Data has been published by the threat actor, confirming exfiltration of regulated medical/PII data at scale, which constitutes a critical HIPAA-relevant breach.LockBit 5 claims to have attacked Crystal Coast Pain Management Center and has published data ('data_published' status), indicating exfiltration of patient and operational records from a medical pain management practice. No ransom amount or specific data volume was disclosed in the post.
Data the group says was taken
AI dossier — extracted from the leak post- Patient medical records
- Patient personal information (PII)
- Referral documentation
- Insurance information
- Medical history and pain assessments
- Procedure and discharge instructions
- Medical records release forms
- Physician/provider contact information
What the group claims
Crystal Coast Pain Management Center specializes in providing a comprehensive range of services for...
Sources
Source
Indexed 4 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

