Quick Summary
AllegedExecutive Summary
Ohio Living Home Health & Hospice, a healthcare organization based in the United States, has been identified as a victim by the Dark Project ransomware group. The listing appeared on the group’s dark web portal on August 5, 2026, and was detected by SOCRadar’s Dark Web Monitoring service. Operating in the home health and hospice care sector, the organization serves a population characterized by a mobile and distributed workforce, which can present unique cybersecurity challenges. This listing marks Ohio Living as one of four healthcare entities claimed by Dark Project within a recent activity period. In the 60 days preceding this listing, Dark Project has claimed a total of 17 victims. The group’s targeting has predominantly focused on the manufacturing, healthcare, and transportation sectors, with a significant concentration of victims located in the United States, the United Kingdom, and the Philippines. Ohio Living Home Health & Hospice’s inclusion aligns with Dark Project’s recent pattern of targeting U.S. healthcare organizations, a trend also observed with other victims such as Mile Bluff Medical Center, The Family Medicine Clinic, Labpharma, and Reid Electric Service, Inc. This consistent targeting of the U.S. healthcare sector suggests deliberate strategic profiling rather than random attacks.
Technical Analysis
SOCRadar’s analysis of stealer-log telemetry related to the ohioliving.org domain revealed a significant exposure. Out of ten records examined in the queried sample, seven (70%) were identified as employee credentials authenticated against Microsoft identity infrastructure for organization-controlled systems. An additional two records indicated corporate users accessing third-party services. This high concentration of corporate credential exposure is noteworthy within the analyzed dataset. The logged activity dates back to early 2025, suggesting that these credentials have been in circulation for an extended period, rather than being a recent development immediately preceding the Dark Project listing. This profile indicates a substantial corporate intrusion risk. For ransomware groups like Dark Project, compromised credentials obtained through infostealers serve as a well-established method for initial access. Threat actors or initial access brokers often acquire credential logs from underground marketplaces, validate them, and then use them to gain unauthorized access to systems such as Microsoft 365, VPNs, or remote-access portals, ultimately deploying ransomware. While the stealer-log data does not definitively confirm that Dark Project utilized these specific credentials for the attack on Ohio Living Home Health & Hospice, access to cloud identity provider credentials represents a highly actionable asset for an attacker. Security teams tracking this incident should consider the exposed corporate identities a persistent risk and prioritize credential rotation and session invalidation as immediate protective measures. Continued dark web and stealer-log monitoring is recommended, along with proactive credential hygiene checks, password rotation, multi-factor authentication review, and monitoring of alternate corporate domains, Microsoft 365, VPN, and remote-access activity.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.