The Heart Center of Memphis Data Breach

Alleged

LockBit 5 claim involving The Heart Center of Memphis

Published: Aug 27, 2026 LockBit
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
The Heart Center of Memphis
Industry
Healthcare
Threat Actor
LockBit
Date of Incident
Aug 27, 2026

Executive Summary

The Heart Center of Memphis, a cardiology practice located in the Memphis, Tennessee region, was listed on LockBit 5’s leak site on August 27, 2026. This incident was identified by SOCRadar’s Dark Web Monitoring service. Healthcare organizations have increasingly become targets for ransomware groups, and a specialized clinic like The Heart Center of Memphis, with its concentrated patient data and potentially less robust security infrastructure compared to larger enterprises, presents an attractive target for opportunistic attacks. In the preceding 60 days, LockBit 5 claimed responsibility for 32 other victims, primarily impacting the technology, professional services, and manufacturing sectors across Germany, the United States, and France. While healthcare is not the group’s most frequent target, The Heart Center of Memphis represents one of the few clinical entities listed in their recent activity. This incident suggests a pattern of opportunistic targeting, where smaller organizations with critical data and potentially weaker security postures are selected by the ransomware group.

Technical Analysis

SOCRadar’s telemetry identified two records associated with theheartcenterofmemphis[.]com, both specifically targeting the organization’s IMAP mail server, imap[.]theheartcenterofmemphis[.]com. A common masked username, mde******o, was found in both entries. The associated password exhibited the same pattern, indicating an unrotated credential that remained active from March through June 2026. The exposure of mail server credentials at a healthcare practice like The Heart Center of Memphis carries significant implications beyond simple email access. Such credentials can provide attackers with access to sensitive patient scheduling information, referral communications, and other critical operational data. This internal network mapping is invaluable for threat actors looking to move laterally within the organization’s systems and ultimately deploy ransomware. The persistent use of an unrotated credential for an extended period highlights a potential vulnerability in the organization’s credential management practices. This type of exposure can serve as an entry point for threat actors, enabling them to gain initial access and gather reconnaissance before initiating a more extensive compromise, potentially leading to a full-scale ransomware attack.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.