On November 3, 2025, the Canadian medical clinic operator bisonfamilymedical.com appeared on the leak site of the ransomware group IncRansom. Internal files were allegedly exfiltrated during a ransomware attack on the small Winnipeg-based provider of family practice and walk-in services.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.
What Public Reporting Shows
Available reporting describes the incident as a ransomware deployment that resulted in data exfiltration. The clinic operates four locations in Winnipeg and employs roughly 10 people. Public details list annual revenue near $5 million. The exposed material consists of internal files; the precise number of patients or employees whose records were taken remains unknown. The primary source is the IncRansom leak site itself, indexed by ransomware.live at the .onion address provided at the end of this article.
Why This Matters for You and Your Family
When a local medical clinic is breached, the information at risk often includes names, addresses, dates of birth, phone numbers, email addresses, and clinical notes. Any of these details can be combined with data from previous breaches to build a profile that criminals sell or use themselves. If you or your family have visited Bison Family Medical Clinics for women’s health services, minor procedures, obstetrics, or virtual care, your records may now sit in an attacker-controlled archive. Medical data is especially sensitive because it can be leveraged for insurance fraud, prescription scams, or targeted phishing that sounds personal and credible.
The Doxxing and Identity-Chain Implications
A single clinic breach rarely stays isolated. Attackers map connections between your clinic email, patient portal login, home address, and other online handles. Once those links exist, one leaked password can cascade into account takeovers across email, banking, and social media. Gaming accounts belonging to children are frequently part of these chains because parents often reuse credentials or store family details in the same password manager. Public reporting indicates that ransomware operators increasingly sell or publish these linked identity packages rather than single records, accelerating doxxing attempts and identity theft.