Quick Summary
AllegedExecutive Summary
Direwolf listed Mission Pet Health on its leak site on September 5, 2026, identified through SOCRadar’s Dark Web Monitoring service. The US-based veterinary care provider is the group’s latest entry in a sustained campaign against American healthcare organizations, following myLaurel, National Kidney Registry, Photon Health, Inc., and PayrHealth in the same 60-day window. Direwolf’s definition of “healthcare” spans human and veterinary medicine. That breadth signals the group isn’t selectively targeting high-payout hospital systems but is running a sustained pressure campaign across the full healthcare vertical, where smaller, less-defended providers are well within scope. The group has claimed 51 victims in the past 60 days, concentrated in Healthcare, Technology, and Financial Services across the United States, Brazil, and Sweden. For organizations in any US-based health or clinical services role, direwolf represents an active, specific threat.
Technical Analysis
Stealer-log telemetry for missionpethealth[.]com returned no records. The query is bounded; exposure may exist under personal aliases or domains outside this sample. No positive signal confirms a clean environment. For direwolf, infostealer-sourced credentials are a viable entry path: harvested logins validated and used against VPN or remote-access portals before deployment. Credential hygiene checks and active monitoring for missionpethealth[.]com remain the appropriate response.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.