Carolina Asthma & Allergy Center Data Breach

Alleged

Ransomware claim involving Carolina Asthma & Allergy Center.

Published: Sep 29, 2026 Chaos
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Carolina Asthma & Allergy Center
Industry
Healthcare
Threat Actor
Chaos
Date of Incident
Sep 29, 2026

Executive Summary

Chaos ransomware has claimed Carolina Asthma & Allergy Center, a specialty respiratory and allergy practice operating across the Carolinas, listing it on its dark web portal on September 29, 2026. SOCRadar’s Dark Web Monitoring service initially identified this listing. The targeting of a healthcare practice aligns with the ransomware group’s observed modus operandi, which includes actively pursuing smaller, specialized providers in addition to larger entities. The Chaos ransomware group has been notably active, claiming 15 other victims within the preceding 60 days. Their activity has been concentrated in the United States, the United Kingdom, and Australia, with a primary focus on the Manufacturing, Healthcare, and Professional Services sectors. Other recent victims cited by the group include Mankato Clinic, Evergen, Healthcare Highways, and Express Employment Professionals. The inclusion of Carolina Asthma & Allergy Center fits within the group’s pattern of targeting the healthcare sector, indicating a continued interest in this industry.

Technical Analysis

SOCRadar’s investigation involved a stealer-log query against the domain carolinaasthma[.]com, which returned no positive results. It is crucial to understand the implications of this null finding: the query represents a bounded, paginated sample of available telemetry and is not a comprehensive audit of all potential credential exposures. Credentials may exist within other data feeds not included in this specific query, or they may be associated with employee personal email addresses rather than the primary corporate domain. Furthermore, healthcare practices often utilize third-party Electronic Health Record (EHR), billing, and patient portal platforms. Domains associated with these external services would likely be missed by a search limited to the main corporate domain. Therefore, a null result from this specific query does not definitively indicate that the organization is unaffected or that no compromise has occurred. The absence of detected records within this limited sample does not rule out the possibility of compromised credentials being used for unauthorized access. Chaos ransomware, similar to many other ransomware operations, typically leverages credentials harvested via infostealers. These credentials are then used to gain initial access to target networks, often through compromised Microsoft 365 accounts, VPN services, or remote-access portals, before the deployment of ransomware. The listing of Carolina Asthma & Allergy Center on the Chaos ransomware leak site strongly suggests a potential compromise, regardless of the outcome of the stealer-log query. The group’s established playbook involves exploiting credential-based access for initial entry. Consequently, organizations in similar situations should conduct a thorough review of their credential hygiene practices. This includes scrutinizing all staff accounts, with particular attention paid to any personal email addresses used for work-related purposes, and maintaining continuous monitoring for any newly exposed credentials.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.