Hudson MD Group, LLC Data Breach

Alleged

MetaEncryptor ransomware claim involving Hudson MD Group, LLC

Published: Sep 21, 2026 MetaEncryptor
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Hudson MD Group, LLC
Industry
Healthcare
Threat Actor
MetaEncryptor
Date of Incident
Sep 21, 2026

Executive Summary

Hudson MD Group, LLC, a medical and clinical services provider based in the United States, was listed on the dark web portal of the MetaEncryptor ransomware group on September 21, 2026. SOCRadar’s Dark Web Monitoring identified this listing, which appeared alongside a cluster of other victims claimed on the same day. The healthcare sector is a frequent target for ransomware groups due to the sensitive nature of the data handled and the critical infrastructure it represents, making organizations like Hudson MD Group potentially attractive targets. In the preceding 60 days, MetaEncryptor claimed approximately 20 victims, with a notable focus on the Manufacturing, Healthcare, and Technology sectors. The group’s primary targeting countries include the United States, South Korea, and Japan. Recent healthcare victims listed by MetaEncryptor include Beckman Coulter, Inc., Hologic, Inc., Visual Intelligence, Inc., and Flex Ltd., indicating a pattern of targeting within the healthcare industry and the US market, aligning with the current incident involving Hudson MD Group.

Technical Analysis

A query conducted by SOCRadar against the domain hudsonmdgroup[.]com for stealer-log records returned zero results. It is important to note that this query was bounded and paginated. Therefore, credentials associated with personal email aliases, specific Electronic Health Record (EHR) systems, or alternative corporate domain names would not be captured by this search. This result should be treated as a lack of positive signal rather than definitive confirmation of no compromise. The absence of stealer-log records for hudsonmdgroup[.]com does not mitigate the risk posed to the organization, especially considering MetaEncryptor’s established pattern of targeting the healthcare sector. The group’s demonstrated activity in targeting clinical organizations within the United States suggests a deliberate focus rather than random opportunism. This observed behavior pattern implies that even without direct evidence from stealer logs for the primary domain, the risk profile remains elevated due to the known threat actor methodologies and the victim’s industry. Monitor hudsonmdgroup[.]com and related sibling domains for any future stealer-log activity. Regardless of the current query results, it is recommended to prioritize auditing credentials for EHR systems, VPNs, and clinical portal access.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.