Quick Summary
AllegedExecutive Summary
Leafwell, a healthcare company operating in the United States, has been listed as a victim by the Direwolf ransomware group. The listing occurred on August 11, 2026, and was identified through SOCRadar’s Dark Web Monitoring service. The incident appears to stem from the exposure of 25 stealer-log records targeting the medicalcard.leafwell[.]com patient portal. The nature of these records, consisting of consumer email addresses or generic handles rather than corporate accounts, suggests a risk of customer account takeover rather than a direct compromise of internal company systems. The Direwolf ransomware group has claimed 11 other victims within the preceding 60 days, with a notable focus on the healthcare sector, followed by financial and professional services. The majority of their targets are located in the United States, with a smaller number in the Philippines and Spain. Previous US-based healthcare victims include AliveCor, Inc., Quironsalud, Health Carousel, and Merge. Leafwell’s inclusion aligns closely with this established targeting pattern of the Direwolf group.
Technical Analysis
SOCRadar’s analysis identified 25 stealer-log records correlated with the leafwell[.]com domain. These records cover a freshness window from July 3 to August 9, 2026, indicating that the exposed credentials had not been rotated for approximately five weeks. Crucially, all affected accounts were customer-facing, specifically related to the patient portal, and utilized consumer email addresses or generic handles, not corporate accounts. This exposure profile points to a widespread risk of customer account takeover for Leafwell’s patients rather than a direct compromise of employee or administrative credentials. While the presence of these logs does not confirm how Direwolf may have gained initial access, it suggests a potential avenue. The absence of corporate credentials within this specific dataset does not rule out their compromise through other means or on different systems. Infostealer-harvested credentials are a known initial access vector for ransomware groups like Direwolf. Threat actors often source credential logs, validate corporate access, and then leverage this access for deploying ransomware. In this instance, the observed exposure is on the customer side of the patient portal, not on employee or administrative accounts. Therefore, the stealer-log evidence does not directly indicate a corporate credential entry path, nor does it confirm the method of Direwolf’s intrusion. The data does not suggest that Leafwell is unaffected, only that this specific query did not reveal corporate credential compromise. Organizations should consider continued dark web monitoring, proactive credential hygiene checks, password rotation, and multi-factor authentication review.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.