Quick Summary
AllegedExecutive Summary
The lockbit5 ransomware group has claimed Tennessee Medical Association, a healthcare organization based in the United States, as a victim. The claim was listed on 2026-08-30. SOCRadar CTI analysis identified two employee credentials in infostealer datasets that appear to be linked to TMA staff, with the most recent activity dated just five days prior to the listing. This proximity between credential exposure and the ransomware group’s claim suggests a potential access path into the organization’s systems. Healthcare organizations, in general, have been consistent targets within the broader threat landscape. In the past 60 days, lockbit5 has claimed 34 victims, primarily targeting organizations in Germany, the US, and France. The group’s sector focus has been on Technology and Professional Services. While healthcare is not lockbit5’s most frequently targeted industry, it remains within their scope. The incident involving the Tennessee Medical Association aligns with the general trend of US-based healthcare entities being targeted by ransomware actors.
Technical Analysis
SOCRadar CTI’s analysis of tnmed[.]org returned a “severe_exposure_in_sample” finding, indicating that two employee credentials were found in infostealer datasets. These credentials were associated with the member portal and an application login endpoint, with timestamps ranging from 2025-05-14 to 2026-08-25. A notable credential flagged was linked to ETSU university, suggesting an employee might be using university-affiliated authentication for access to Tennessee Medical Association systems. This cross-domain credential linkage potentially broadens the attack surface beyond what isolated credential rotation at tnmed[.]org would address. The close temporal proximity between the identified credential exposure and the lockbit5 listing is a significant indicator. The presence of a live credential captured just five days before the ransomware group’s claim points to a plausible initial access vector. Infostealer-harvested credentials can directly support ransomware operations by providing attackers with authenticated access to victim networks, bypassing the need for more complex intrusion methods. The exposed credentials must be rotated immediately across both Tennessee Medical Association and ETSU systems. Organizations should review member portal and application login access logs for any anomalous authentication activities occurring in the weeks leading up to 2026-08-30. For a healthcare association, the implications of unauthorized data access could extend beyond IT systems, potentially compromising member and physician records. Continued monitoring of dark web and stealer-log data for relevant credentials is also recommended.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.