On October 19, 2025, the Blood and Marrow Transplant Group of Georgia appeared on the leak site of the qilin ransomware group. The medical practice, which treats patients needing blood and marrow stem cell transplants, acute leukemia care, and CAR T-cell immunotherapy, is claimed to have had internal files exfiltrated during a ransomware attack. While the exact number of patients and staff affected remains unknown, any individual whose medical records, personal details, or financial information passed through the practice could now have that data circulating among criminals.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch The Blood and Marrow Transplant Group
Get alerted the next time The Blood and Marrow Transplant Group files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about The Blood and Marrow Transplant Group’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Reported Details of the Incident
Public reporting indicates that qilin operators listed BMTGA after the group failed to meet an extortion deadline. The attackers claim to have stolen internal files during the breach. No precise volume of records has been disclosed, and the precise data types have not been independently verified beyond the attackers’ description of “internal files.” The incident follows the typical ransomware pattern of encryption, followed by data exfiltration and public shaming when payment is not received.
Why This Matters for You and Your Family
Medical practices hold some of the most sensitive information about you and your loved ones: names, dates of birth, Social Security numbers, insurance details, diagnoses, treatment histories, and sometimes home addresses and phone numbers. When these records are stolen, identity thieves can open fraudulent accounts, file fake tax returns, or sell the data on underground markets. For families dealing with serious illnesses such as leukemia or those who have undergone transplants, the exposure adds emotional strain to an already difficult situation. Even if you were not the direct patient, a spouse, child, or parent listed as an emergency contact can still have their information compromised.
The Doxxing and Identity-Chain Risks
Stolen medical data rarely stays isolated. Criminals combine it with information from other breaches to build detailed profiles. A username found in one leak can link to an email address, which links to a phone number, which leads to social-media accounts and eventually to physical addresses. This identity-chain process turns a single breach into long-term exposure. Public reporting shows that healthcare breaches frequently cascade into doxxing campaigns, harassment, or targeted scams against patients and their families. Gaming accounts belonging to children are especially vulnerable because kids often reuse email addresses or passwords tied to family medical portals; once those credentials appear in a ransomware dump, the chain can reach family Xbox, PlayStation, or Roblox accounts within hours.