Barracuda Claims 447GB Clinical Associates of the Finger Lakes Data Leak

Barracuda ransomware claims to have leaked 447 GB from Clinical Associates of the Finger Lakes, including children's medical records and internal email data.
Barracuda ransomware forum post claiming a 447 GB data leak from Clinical Associates of the Finger Lakes containing children's medical records and other sensitive data.
Barracuda claims it stole and leaked 447 GB of data from Clinical Associates of the Finger Lakes, including children's medical records, parent and employee information, and email server data.

Barracuda ransomware claims to have stolen and leaked 447 GB of data from Clinical Associates of the Finger Lakes, a New York provider of pediatric clinical, therapeutic and educational services.

The group alleges it extracted files and documents from CAFL’s infrastructure, including children’s medical records, personal information belonging to parents and employees, and a complete dump of email data from the organization’s mail server.

Evidence published by Barracuda appears to show pediatric evaluation records, Early Intervention documentation, special education records, parent or guardian consent forms and directories containing files associated with children and staff. BreachNews is not reproducing names, dates of birth, contact information or other personally identifiable information visible in the material.

Leaked samples appear to contain children’s records

The sensitivity of the material shown in Barracuda’s evidence makes the claim particularly serious. Screenshots reviewed by BreachNews appear to contain documents associated with children receiving developmental, educational and clinical services.

Visible document categories include Early Intervention evaluations, parent interviews, preschool special education records, consent forms and clinical assessment material. Some records appear to contain information concerning children’s development and eligibility for services.

The screenshots also show directories containing numerous files apparently organized around individual clients and clinical or educational documentation.

Barracuda claims the complete archive totals approximately 447 GB and includes:

  • Children’s medical and clinical records
  • Early Intervention and special education documentation
  • Personal information belonging to parents and guardians
  • Employee information
  • Email server data
  • Other internal files and documents

The ransomware group claims it extracted all files and documents from the affected infrastructure, but BreachNews has not independently verified that assertion or the claimed 447 GB volume.

CAFL provides services to infants and preschoolers

Clinical Associates of the Finger Lakes provides therapeutic and educational services to children and families across multiple counties in upstate New York.

According to CAFL’s website, its services include speech-language therapy, occupational therapy, physical therapy, special education and behavioral support, assistive technology and evaluations.

The organization works with infants, toddlers and preschool-aged children with developmental needs and participates in Early Intervention and preschool special education programs.

CAFL says it employs more than 120 staff members and works with families, school districts, Early Intervention programs, physicians and other professionals.

The organization also maintains a dedicated privacy section addressing the protection of children’s records and data privacy requirements associated with its educational services.

Email archive could broaden potential exposure

Barracuda’s claim that it obtained a full email-server dump could potentially expand the scope of exposed information beyond records stored in individual client directories.

Email systems at healthcare and educational organizations can contain communications between staff, families, schools and other service providers, as well as attachments and operational information. However, the contents and completeness of the email data claimed by Barracuda have not been independently verified.

The combination of pediatric records, parent information and internal communications could create significant privacy risks if the group’s claims are accurate.

Medical and developmental information involving children is particularly sensitive because it can remain private and personally consequential for years. Contact and identity information belonging to parents or employees could also potentially be used for targeted phishing, impersonation or other social engineering attacks.

Barracuda publishes data after ransomware claim

Barracuda has moved beyond simply naming CAFL as an alleged victim and claims the organization’s data is now being distributed through its leak infrastructure.

Clinical Associates of the Finger Lakes listing on the Barracuda ransomware data leak site claiming 447 GB of stolen data.
Barracuda’s data leak site lists Clinical Associates of the Finger Lakes as a victim and advertises a 447 GB archive for download.

The group published screenshots as evidence of the alleged compromise alongside its description of the 447 GB archive. The material shown by Barracuda appears consistent with the types of pediatric clinical and educational services CAFL publicly says it provides, although that alone does not establish the completeness or origin of the entire claimed archive.

Clinical Associates of the Finger Lakes had not issued any public statement confirming the ransomware group’s claims at time of publication.

Picture of m00s3c

m00s3c

Moose (@m00s3c) is the author of BreachNews, focusing on data breach intelligence, dark web monitoring, and threat analysis. His work involves analyzing breach claims, reviewing leaked datasets, and tracking threat actor activity to provide clear, factual reporting.

Latest News

BREACHNEWS.COM/SUPPORT/

Support Independent News.

Help support breach monitoring, investigations, infrastructure, and reporting.

Support the site