The Harry Perkins Institute of Medical Research was listed on the Medusa ransomware group’s leak site on 7 July 2024. The Australian medical research organisation, which employs 172 staff and focuses on major health challenges, had 4.6TB of internal building camera recordings uploaded by the attackers. The disclosure indicates that additional internal files were also exfiltrated during the ransomware incident, although the exact volume and full range of data types remain unknown.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.
Reported Details from the Listing
The Medusa leak site entry states that the Harry Perkins Institute of Medical Research suffered a ransomware attack in which internal files were exfiltrated. It specifically notes that 4.6TB of internal building camera recordings have been published. The listing does not quantify the total number of affected individuals, nor does it itemise every category of data taken. Public access to the leak site via ransomware.live states the posting date as 7 July 2024. No ransom demand figure or payment deadline is shown in the available primary disclosure.
Why This Matters for You and Your Family
When a medical research institute is hit, the consequences reach far beyond the organisation itself. Staff, patients, research partners, and donors may have personal information entangled in the compromised environment. Even if the published material is limited to camera footage today, the breach signals that attackers successfully entered the network and removed data. For ordinary people whose records sit inside such institutions, this creates a persistent risk that sensitive details could surface later. Your medical history, contact information, or employment records held by the institute could be used for identity theft, phishing, or harassment if further material is released.
The Doxxing and Identity-Chain Risk
Camera recordings from inside a building often capture faces, movements, vehicle registrations, and daily routines. When combined with any internal documents that list names, emails, or phone numbers, attackers can quickly link physical identities to digital ones. These connections form identity chains that stretch across social media, gaming accounts, and family relationships. A single leaked work email can lead to personal accounts, and children’s gaming usernames tied to the same household address become easy follow-on targets. Public reporting on similar incidents shows that such chains frequently result in doxxing, account takeovers, and sustained harassment.