On March 31, 2026, pharmacy benefit management company MC-Rx appeared on the leak site of the Genesis ransomware group, with attackers claiming to have exfiltrated internal files from the organization formerly known as MC-21 and ProCare PBM.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch MC-Rx
Get alerted the next time MC-Rx files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about MC-Rx’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Reported Details of the Breach
Public reporting indicates the incident involves a ransomware attack in which Genesis operators say they stole internal company files. The exact number of people affected remains unknown, and the precise data types have not been fully detailed in available listings. The company provides pharmacy benefit management services, handling prescription drug coverage for insurers, employers, and patients. As of the listing date, March 31, 2026, the files were posted on the Genesis leak site hosted on the dark web.
Why This Matters for You and Your Family
When a pharmacy benefit manager is breached, the information at risk often includes prescription records, insurance details, Social Security numbers, addresses, and payment information tied to your health coverage. This kind of personal health and financial data can be used to commit identity theft, file fraudulent claims, or target you with highly personalized scams. For families, a single breach can expose every household member listed on the same insurance plan, including children. Once your information is loose on criminal forums, it rarely disappears and can resurface years later.
The Doxxing and Identity-Chain Risks
Credential leaks and internal files from healthcare vendors frequently cascade into larger doxxing campaigns. Attackers combine exposed emails, phone numbers, and policy details with data from other breaches to map your online handles to your real identity. This chain can lead to account takeovers on email, banking, or social media, and in some cases extends to gaming accounts where children use family email addresses or shared phones. Public reporting shows these identity chains accelerate harassment, swatting, and extortion once a clear link between your digital life and physical address is established.