Union for International Cancer Control Data Breach

Alleged

Ransomware claim involving Union for International Cancer Control.

Published: Sep 1, 2026 Krybit
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Union for International Cancer Control
Industry
Non-profit
Threat Actor
Krybit
Date of Incident
Sep 1, 2026

Executive Summary

The Union for International Cancer Control (UICC), a global civil society organization headquartered in Switzerland focused on advancing cancer control through various initiatives, was listed on the krybit ransomware group’s dark web portal on September 1, 2026. This listing was detected by SOCRadar’s Dark Web Monitoring. The targeting of a global health NGO is a notable event, given that such organizations often handle sensitive research and partnership data, making them potentially attractive targets for cybercriminals. In the preceding 60 days, the krybit ransomware group claimed 58 other victims. Their primary targets include organizations within the Professional Services, Other, and Technology sectors, with a geographical concentration in India, Thailand, and Brazil. The UICC, as a Professional Services organization based in Switzerland, aligns directly with krybit’s prevalent targeting profile. Previous victims of krybit in the Professional Services and NGO-adjacent space include Southsign Technologies, Jigme Singye Wangchuck School of Law, APSA Internacional S.A., and Studio Associato Tibaldi.

Technical Analysis

SOCRadar’s query into stealer-log data for the domain uicc[.]org yielded limited results. Specifically, three records were identified on ecampus.uicc[.]org, which is the UICC’s e-learning portal. These records indicated a “Customer ATO” profile, meaning the compromised credentials belonged to customers using consumer email addresses (Outlook and Yahoo domains) rather than official UICC corporate email addresses. Crucially, no employee credentials were found in the queried data slice. However, the limited scope of the eCampus domain query means that corporate credentials might exist under other UICC-controlled domains or within data feeds not included in this specific analysis. The presence of customer ATO findings on eCampus suggests that stealer malware was active on devices that accessed UICC’s externally-facing services. Given UICC’s profile as an international NGO dealing with sensitive data, it is recommended that the organization audit eCampus access logs for any anomalous sessions. Additionally, continuous monitoring of the uicc[.]org domain across broader credential feeds is advised to detect any potential further compromise or misuse of exposed information.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.