Quick Summary
AllegedExecutive Summary
Maryann Kriger, an entity operating under bonitaortho[.]com, was listed by the INC Ransom ransomware group on their leak portal on September 21, 2026. This detection was made possible by SOCRadar’s Dark Web Monitoring service. The primary actionable intelligence found was in the form of six stealer-log records, spanning from December 2025 to August 2026, which indicated credential exposure across both an internal staff portal and external consumer accounts. Given the nature of orthopedic medical practices, they can be attractive targets due to the sensitive patient data they handle and their reliance on digital infrastructure. INC Ransom has claimed 68 other victims in the preceding 60 days, showing a strong focus on the Manufacturing, Professional Services, and Healthcare industries, with a predominant geographic concentration in the United States and Canada. Previous entities listed by INC Ransom with a similar profile, such as small US-based practices, include Zummo, vprj.org, Samuels & Thornton, and Kendall Hunt Publishing. This pattern suggests that Maryann Kriger aligns with the threat actor’s typical targeting strategy.
Technical Analysis
SOCRadar’s analysis identified six stealer-log records associated with Maryann Kriger, dated between December 2025 and August 2026. These records pertained to the domain bonitaortho[.]com. Among these findings, one employee credential was observed to have remained unchanged across three records within July and August 2026, indicating a potential persistent compromise of an internal staff portal or similar access point. Additionally, one record flagged a geolocation of Egypt, suggesting possible external access to the exposed credential. The presence of an unrotated staff credential is a significant finding. Its recurrence over a two-month period strongly suggests an ongoing, unaddressed workstation compromise. The Egypt geolocation further points to the possibility that this credential has already been accessed and potentially utilized from outside the victim’s assumed network perimeter. INC Ransom is known to leverage access obtained from initial access brokers (IABs), and the profile presented here—an unrotated staff credential with external access indicators—fits this modus operandi closely. Immediate actions recommended for Maryann Kriger include rotating all credentials associated with bonitaortho[.]com, conducting a thorough audit of the ‘/team’ endpoint for any unauthorized active sessions, and initiating an investigation into the specific access event flagged with an Egypt geolocation.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.