MedEvolve Data Breach

Alleged

Ransomware claim involving MedEvolve

Published: Sep 3, 2026 Settra
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
MedEvolve
Industry
Healthcare
Threat Actor
Settra
Date of Incident
Sep 3, 2026

Executive Summary

MedEvolve, a U.S. company that provides technology and workflow solutions to healthcare organizations through its domain medevolve[.]com, was identified on September 3, 2026, as a victim on the settra ransomware group’s dark web portal. SOCRadar’s Dark Web Monitoring service detected this listing, which aligns with settra’s recent trend of targeting U.S. healthcare technology firms. The nature of MedEvolve’s business, which involves sensitive healthcare data and operates within a regulated sector, makes it a potentially attractive target for ransomware operations. The settra ransomware group has claimed 32 other victims in the 60 days preceding this listing. Their primary targets are in the United States, followed by Germany and the United Kingdom. The industries most frequently affected by settra include technology, professional services, and manufacturing, with healthcare organizations also appearing among their victims. Previous U.S. victims of settra exhibiting similar patterns include Zonar Systems (transportation), GT Telecom (technology), ALPHANUMERIC SYSTEMS (information services), and Diversified Body Acquisition (manufacturing). The inclusion of MedEvolve on settra’s leak site is consistent with the group’s established targeting of mid-market U.S. companies, with the healthcare technology focus adding specific regulatory and patient data sensitivities to the incident.

Technical Analysis

SOCRadar’s analysis of stealer-log telemetry returned no records specifically associated with the domain medevolve[.]com within the queried dataset. It is important to note that a null result from this specific query does not definitively confirm that the organization is unaffected. The query covers a paginated sample of available logs, and credentials could exist under alternate corporate domains or have been associated with personal email aliases. Furthermore, records might reside in threat intelligence feeds not included in the queried dataset, or credentials might have been used and subsequently rotated before being indexed. The absence of immediate telemetry does not rule out potential compromise. Infostealer-harvested credentials, if obtained through other means, can significantly lower the barrier for initial access in ransomware operations. These credentials, potentially exfiltrated from compromised endpoints or services, could be used for gaining unauthorized access to corporate networks, including sensitive systems like Microsoft 365, VPNs, or remote-access portals. This access can then pave the way for further reconnaissance, lateral movement, and eventual ransomware deployment. Given these considerations, continued monitoring for MedEvolve is recommended. This includes ongoing dark web and stealer-log monitoring, proactive credential hygiene checks, and a thorough review of password rotation policies and multi-factor authentication implementation across all critical systems. Monitoring of alternate corporate domains and reviewing activity logs for Microsoft 365, VPNs, and other remote-access solutions are also crucial steps to detect any potential compromise.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.