A North Carolina lab was removed from the ransomware group's leak site months after the attack, a detail that suggests a ransom was paid even though the company has never confirmed it.
What happened
Marlboro-Chesterfield Pathology, a Pinehurst, North Carolina-based molecular, cytology, and pathology laboratory, has agreed to settle a class action lawsuit over a January 2025 ransomware attack attributed to the SafePay group. According to BankInfoSecurity, the lab identified unauthorized network access on January 16, 2025, and reported to HHS on May 9 that 235,911 individuals had their data compromised, including names, dates of birth, Social Security numbers, and protected health information. Affected individuals were notified around May 7, 2025. The settlement, reached in the case Cox v. Marlboro-Chesterfield Pathology, P.C. in Moore County Superior Court, received preliminary court approval on May 22, 2026. The claims deadline and opt-out deadline are both August 21, 2026, with a final approval hearing scheduled for October 12, 2026.
Going deeper
Marlboro-Chesterfield Pathology stated in its original breach notice that it discovered unauthorized activity on some of its internal IT systems on January 16, 2025, and that an investigation confirmed hackers had stolen files containing personal information, with the specific data compromised varying by individual. The notice states: "We took prompt action and quickly engaged third-party specialists to assist us in securing our systems and investigating the incident. Law enforcement is aware of the incident, and we have cooperated with their investigation. The involvement of law enforcement did not delay this notification. Through a thorough investigation and extensive review of the impacted data, which concluded on March 31, 2025, we determined that some of your personal information was contained in the affected records."
What was said
Plaintiff Cox alleged the ransomware attack resulted directly from Marlboro-Chesterfield Pathology's failure to implement reasonable cybersecurity measures to protect patient data on its network. In its settlement filing, the lab maintains it disagrees with the claims and contentions in the lawsuit but entered settlement discussions after arm's-length negotiations concluded terms acceptable to both parties on November 21, 2025.
In the know
SafePay claimed responsibility for the attack in late January 2025 and initially listed Marlboro-Chesterfield Pathology on its dark web leak site. According to SecurityWeek, the lab no longer appeared on that leak site by the time of its reporting, a pattern that in prior SafePay cases has coincided with a ransom payment, though Marlboro-Chesterfield Pathology has never confirmed making one. SafePay has run a sustained campaign against healthcare and business services targets, having also claimed responsibility for the breach at Conduent Business Services, which we previously reported grew to affect more than 62 million individuals across the healthcare sector.
The big picture
A diagnostic laboratory holds a specific category of data that compounds the risk when a breach occurs. Pathology results reveal cancer diagnoses, biopsy findings, and other clinical determinations that patients often have not yet fully processed themselves, let alone disclosed to employers or insurers, at the exact moment that data ends up in the hands of a ransomware group. According to BankInfoSecurity, SafePay has already conducted well over 150 confirmed attacks since emerging, with healthcare and diagnostic laboratories among its recurring target categories. For a lab serving both North and South Carolina, the settlement's one-year credit monitoring term reflects the more limited scope of financial identifiers exposed compared to breaches that also include ongoing medical account access, but it does nothing to address the separate and more personal exposure of a pathology diagnosis itself becoming known outside the clinical relationship where it was meant to stay.
FAQs
Why would SafePay remove Marlboro-Chesterfield Pathology from its leak site without the lab confirming a ransom payment?
Ransomware groups operating a double-extortion model typically remove a victim from their public leak site once a ransom has been paid, since the threat of publication was the primary advantage. Organizations rarely confirm payment publicly due to the legal and reputational complications involved, even when the removal strongly suggests one occurred.
What makes pathology lab data different from a standard medical record breach?
A pathology report often contains a diagnosis before the patient has had a full conversation with their physician about what it means, and before they have decided who else in their life to tell. When that data is stolen, the exposure includes not just identifying information but a clinical determination that the patient may not have processed or disclosed on their own terms.
How does the SafePay connection to the Conduent breach affect how this incident should be understood?
SafePay's involvement in both the Marlboro-Chesterfield Pathology breach and the much larger Conduent Business Services breach shows the same ransomware group operating across dramatically different scales, from a single regional lab to a vendor whose breach eventually affected tens of millions of people. Both incidents originated from the same group's opportunistic targeting rather than any specific vulnerability unique to healthcare pathology providers.
