On July 4, 2024, the Quebec speech therapy clinic Un Museau vaut mille Mots appeared on the leak site operated by the spacebears ransomware group. The listing states that internal files were exfiltrated during a ransomware attack. The clinic provides telespeech therapy to children, adolescents, and adults across Quebec and is part of the Haylem network, which develops the Lexibar software for reading and writing difficulties. The disclosure indicates that the stolen material includes financial reports, a database, and patient histories containing personal information. The number of affected individuals remains unknown.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Un Museau
Get alerted the next time Un Museau files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Un Museau’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Details from the Leak Site
The primary disclosure on the spacebears onion site lists Un Museau vaut mille Mots as a victim and confirms that attackers extracted internal files after gaining access to the clinic’s systems. The listing does not quantify the volume of data taken or name every file type beyond referencing financial reports, the clinic’s database, and patient histories. No ransom demand figure is published on the page, and the exact date of initial compromise is not stated. The entry simply states that exfiltrated material is held by the group and implies it will be released if demands are not met.
Why This Matters for You and Your Family
If you or your child received speech therapy services from Un Museau vaut mille Mots, your personal details and medical history may now sit in an attacker’s archive. Patient histories often contain names, dates of birth, contact information, insurance details, and clinical notes that describe family circumstances. When this information reaches dark-web markets or is dumped publicly, it becomes raw material for identity theft, targeted scams, and long-term fraud. Families who used the clinic’s telespeech services from home may also have shared additional household data that increases the exposure. Even though the exact number of records is not disclosed, the nature of a speech therapy practice focused on children makes the breach especially sensitive for parents protecting young identities that lack established credit histories.
Doxxing and Identity-Chain Risks
Medical and financial records rarely exist in isolation. A single leaked patient file can link a child’s name and birthdate to a parent’s email address, phone number, and home region. Attackers then cross-reference these details with credential leaks from other services, building an identity chain that can reach gaming accounts, school portals, and social media profiles. Once the chain is established, doxxing escalates quickly: addresses are published, family members are harassed, or fraudulent accounts are opened in a child’s name. Credential leaks of this kind frequently cascade into account takeovers precisely because the same password used to log into a patient portal may protect an email account or a child’s Roblox or Minecraft profile.