National Kidney Registry Data Breach

Alleged

Ransomware claim involving National Kidney Registry

Published: Aug 25, 2026 Direwolf
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
National Kidney Registry
Industry
Healthcare
Threat Actor
Direwolf
Date of Incident
Aug 25, 2026

Executive Summary

A corporate credential linked to the National Kidney Registry was detected in stealer-log telemetry on August 22, 2026. Three days later, the Direwolf ransomware group listed the organization on its dark web portal, an event identified by SOCRadar’s Dark Web Monitoring service. The National Kidney Registry, a US-based nonprofit, plays a critical role in coordinating kidney paired donation and living donor organ exchange programs. The sensitive nature of the patient health information, donor matching records, and transplant coordination data it holds makes it a high-value target for threat actors. Direwolf has demonstrated significant activity in recent months, claiming 40 other victims within the preceding 60 days. Its primary operational geographies include the United States, Mexico, and Sweden, with a pronounced focus on the Technology, Healthcare, and Financial Services sectors. Notable recent victims within the healthcare and professional services sectors include Photon Health Inc., PayrHealth, Colla Health, and Leafwell. US healthcare organizations represent Direwolf’s most consistent targeting category, aligning precisely with the National Kidney Registry.

Technical Analysis

A query to kidneyregistry[.]com returned one record: a corporate credential for an @kidneyregistry[.]com email address. This credential was authenticated against Adobe’s identity service (auth.services.adobe[.]com) and logged on August 22, 2026. It is highly probable that the device associated with this credential was infected by an infostealer, which subsequently harvested credentials for both corporate and third-party services. A compromise of Adobe authentication can potentially enable lateral movement within Adobe-integrated workflows or contribute to broader credential-reuse patterns across Software as a Service platforms. The profile of this finding is a workstation compromise risk, with the credential being fresh as of August 22, 2026. The three-day interval between the credential exposure in stealer-log telemetry and the Direwolf listing on its leak site is sufficiently short to consider the credential operationally relevant until proven otherwise. Infostealer-derived credentials are a primary initial access vector for Direwolf. Threat actors typically have these credentials validated against platforms such as Microsoft 365, VPNs, or remote-access portals before they are sold or utilized for further intrusion. Immediate investigation of the affected endpoint and a thorough audit of all internal systems reachable from it are recommended. Given the highly sensitive nature of patient and donor data managed by the National Kidney Registry, parallel review of compliance requirements and potential breach-notification obligations is also advised.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.