Quick Summary
AllegedExecutive Summary
InfoFlo CRM, a provider of customer relationship management software based in the United States, was recently listed as a victim by the DireWolf ransomware group. The incident was identified by SOCRadar’s Dark Web Monitoring on August 19, 2026. As a CRM vendor, a breach at InfoFlo CRM poses significant risks not only to the company itself but also to its extensive client base, particularly those in the healthcare sector. The sensitive data typically managed by CRM systems, including contact lists, sales pipelines, and potentially patient records for healthcare clients, could be exposed. This downstream impact across InfoFlo’s clients is a primary concern arising from this listing. The DireWolf ransomware group’s activity on August 19, 2026, also included claims against Lifesum, a healthcare technology company in Sweden, and Photon Health, Inc., a healthcare entity in the US, alongside PayUp in Financial Services. This pattern indicates a consistent targeting of the healthcare and financial technology sectors by DireWolf. InfoFlo CRM’s specific focus on the healthcare market makes its inclusion in this batch a deliberate targeting rather than a random occurrence, aligning with the group’s established operational patterns.
Technical Analysis
SOCRadar’s Dark Web Monitoring identified a listing for InfoFlo CRM on the DireWolf ransomware group’s portal on August 19, 2026. A query into stealer logs specifically targeting the domain infoflo[.]com yielded no direct records. It is important to note that this result does not confirm that the organization is unaffected. The query was paginated and limited in scope. Consequently, credentials may still exist under related or subsidiary corporate domains that were not included in this specific search, or through personal email aliases used by staff members. Such records may also reside in datasets not queried by SOCRadar or may have been used and subsequently rotated before their indexing. The absence of records in this particular stealer-log query does not rule out the possibility of a compromise. Infostealer-harvested credentials can be a valuable commodity for threat actors, providing initial access pathways for ransomware operations. Compromised credentials can be validated and used to gain unauthorized access to corporate networks, potentially through Microsoft 365 accounts, VPNs, or other remote-access portals. While this specific query did not directly link InfoFlo CRM to exposed credentials that could support a ransomware attack, the possibility remains open. Given the nature of this threat, continued monitoring of dark web and stealer-log feeds for InfoFlo CRM and its associated domains is recommended. Proactive credential hygiene, including regular password rotation and multi-factor authentication reviews, should be a priority. Additionally, vigilance in monitoring Microsoft 365, VPN, and remote-access portal activity for any anomalous behavior is advised.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.