Quick Summary
AllegedExecutive Summary
Chaos has listed Healthcare Highways, a US healthcare company, on its leak portal in a post published August 4, 2026, flagged through SOCRadar’s Dark Web Monitoring service. SOCRadar’s dataset categorizes the organization within the healthcare industry, specifically in network and benefits administration. This segment operates between payers, providers, and employers, giving it access to data on populations significantly larger than its own employee base. This profile aligns with Chaos’s recent activities, which predominantly target US entities and the healthcare sector. Chaos has claimed 13 other victims in the 60 days preceding this listing. Its targeting has been observed in technology, healthcare, and business services sectors, with a strong concentration of victims in the United States, alongside single instances in the United Kingdom, Germany, and Singapore. Notable recent victims in the US healthcare and life sciences sectors include Neopharm Labs, Aphena Pharma Solutions, CorePharma, and Wikoff Color Corporation. While the raw volume of victims may seem moderate, the significant proportion of healthcare and pharmaceutical entities targeted is a critical concern for defenders in this sector.
Technical Analysis
Stealer-log telemetry revealed a significant exposure for healthcarehighways[.]com. The queried sample returned six records, comprising four employee credentials for internal organization systems and two for external or third-party accounts. The critical endpoints identified were content-management administration paths on the organization’s own domain, with one login surface exposed on a non-standard port. This configuration often suggests a legacy deployment or a persistence artifact, pointing towards a high corporate intrusion risk. The recorded data ranges from August 2025 to March 17, 2026. Notably, the same administrative usernames recur throughout these seven months without any indication of rotation. For threat groups like Chaos, credentials harvested by infostealers represent a common initial access vector. Threat actors or initial access brokers typically source fresh logs from underground marketplaces, validate the corporate credentials, and then use them to log into platforms such as Microsoft 365, VPNs, or remote-access portals before deploying ransomware. While the stealer-log evidence does not definitively confirm that Chaos specifically utilized these credentials, the pattern aligns with the typical kill chain for such incidents: administrative access to an internet-facing web platform, maintained for an extended period. It is important to note that the absence of records after March 2026 does not imply remediation or a lack of compromise, but rather marks the limit of the queried data sample.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.