#HealthcareAttack
Royal Bahrain Hospital, a key healthcare facility serving Bahrain and neighboring countries, was hit by a ransomware attack that encrypted its systems. Incident discovered in March 2026. #Bahrain #HealthcareAttack #Ransomware
Ransom! Royal Bahrain Hospital (MAR-2026)
A ransomware claim alleges Royal Bahrain Hospital (RBH) in Bahrain was targeted by a payload threat actor and hospital systems were encrypted. RBH, established in 2011, is a 70-bed facility offering inpatient and outpatient care and serves Bahrain and neighboring countries such as Oman, Qatar, Saudi Arabia, and the UAE. #Bahrain
www.hendryadrian.com
March 15, 2026 at 3:00 PM
The Genesis ransomware group has encrypted systems and potentially exposed patient data in a healthcare organization. Details on location and breach extent remain undisclosed. #DataBreach #HealthcareAttack #RansomwareIncident
Ransom! *** (APR-2026)
Genesis has claimed a ransomware operation targeting a healthcare organization, encrypting systems and potentially exposing patient data. Details on the geographic impact and full extent of the breach are not publicly disclosed. #unknown
www.hendryadrian.com
April 18, 2026 at 3:45 PM
The American Board of Preventive Medicine suffered a ransomware attack by the Genesis group, disrupting healthcare certification services across the United States. Incident discovered May 9, 2026. #HealthcareAttack #RansomwareUS #UnitedStates
Ransom! The American Board of Preventive Medicine (MAY-2026)
The American Board of Preventive Medicine, a healthcare certification organization in the US, reported a ransomware incident attributed to the Genesis threat actor. The attack disrupted access to systems and services, impacting operations in #UnitedStates
www.hendryadrian.com
May 9, 2026 at 1:45 PM
Insomnia ransomware targets Nephrology Associates, PA, encrypting patient records across seven Arkansas locations. Threat actor demands ransom or threatens to leak sensitive healthcare data. #HealthcareAttack #Ransomware #UnitedStates
Ransom! Nephrology Associates (APR-2026)
Insomnia claims to have compromised Nephrology Associates, PA, a leading central Arkansas nephrology practice, encrypting patient records across seven locations. The threat actor warns that if the ransom isn't paid, sensitive information will be leaked or sold. #UnitedStates
www.hendryadrian.com
April 28, 2026 at 9:30 PM
Meena Health falls victim to a ransomware attack by Killsec. Ransom amount remains undisclosed. Threat includes data release or file encryption with 0 out of 1 disclosures made so far. #HealthcareAttack #Killsec #Ransomware
Ransom! meena health (MAR-2026)
Meena Health reports a ransomware incident attributed to Killsec, with the ransom price marked as ??? and disclosures 0/1. The extortion note threatens data release or encryption of files but provides no disclosed payment amount or method. #Unknown
www.hendryadrian.com
March 14, 2026 at 8:20 AM
Neurotrials Research Inc, an Atlanta-based clinical research facility, suffered a ransomware attack linked to the Sinobi group, disrupting operations amid ongoing clinical trials with 2,500+ volunteers. #HealthcareAttack #DataBreach #Atlanta
Ransom! Neurotrials Research Inc (MAY-2026)
Neurotrials Research Inc, an Atlanta-based outpatient and inpatient clinical research facility, reported a ransomware incident attributed to the sinobi threat actor. Founded in 1997 and supporting 175+ clinical trials with 2,500+ volunteers, the organization stated that the attack impacted its operations, with the impacted country(s) listed as: # (unknown)
www.hendryadrian.com
May 8, 2026 at 11:45 PM
Cherry Health in Grand Rapids, Michigan faces a tech outage disrupting phone systems, under investigation as a possible cyberattack. Clinics remain open; no patient data breach confirmed yet. #CherryHealth #HealthcareAttack #USA
Cherry Health outage in Michigan investigated as possible cyberattack
Cherry Health, a healthcare provider in Grand Rapids, Michigan, is experiencing a widespread technology outage that has disrupted its phone system and prompted an investigation as a possible cyberattack. Clinics remain open for scheduled appointments, and Cherry Health has not confirmed whether patient data were compromised; the outage follows a ransomware incident reported in late 2023. #CherryHealth #GrandRapids
www.hendryadrian.com
April 29, 2026 at 5:15 PM
Virginia Health Services, a healthcare provider in Hampton Roads, VA, was hit by a ransomware attack from worldleaks, risking patient data exposure and disrupting senior care and rehabilitation services. #HealthcareAttack #DataBreach #UnitedStates
Ransom! Virginia Health Services (MMM-YYYY, example JAN-2026 from this date 2026-04-23 10:54:17.239362)
The ransomware claim from worldleaks alleges that Virginia Health Services, a Virginia-based healthcare provider in the United States, was breached, potentially exposing patient data and disrupting operations. Virginia Health Services delivers senior care, rehabilitation, memory care, and outpatient therapy across multiple facilities in the Hampton Roads region, and the claim suggests significant disruptions to care and data security. #UnitedStates
www.hendryadrian.com
April 23, 2026 at 2:45 PM
Nordenta, a Danish healthcare subsidiary of LIFCO, faces a ransomware claim by threat actor Kairos. The attack references Nordenta and Al Dente newsletters. Beneficial owner: Carl Bennet. #Denmark #HealthcareAttack #RansomwareIncident
Ransom! Nordenta (a daughter company of LIFCO) (APR-2026)
A ransomware claim targets Nordenta, a Danish subsidiary of LIFCO, and is attributed to the threat actor Kairos. The claim references Nordenta and Al Dente newsletters, includes consent language for receiving offers and information by email, and states that the beneficial owner of Nordenta is Carl Bennet. #Denmark
www.hendryadrian.com
April 21, 2026 at 11:45 AM
ViaQuest, a US care provider for seriously ill patients, suffers a large-scale ransomware attack by Anubis, exposing sensitive patient data across its systems. #DataBreach #HealthcareAttack #UnitedStates
Ransom! ViaQuest (APR-2026)
ViaQuest, a US-based care provider for seriously ill patients, reports a large-scale data breach attributed to the Anubis threat actor. The claim describes ransomware-style access leading to exfiltration of patient data across ViaQuest's systems #UnitedStates
www.hendryadrian.com
April 21, 2026 at 4:45 AM
Kairos threat actor has compromised FriendlyCare Pharmacy in Australia, encrypting systems and possibly exfiltrating customer data. A ransom demand includes threats of public exposure if unpaid. #Australia #HealthcareAttack #DataBreach
Ransom! FriendlyCare Pharmacy (APR-2026)
The claim states that the threat actor Kairos compromised FriendlyCare Pharmacy in Australia, encrypting systems and potentially exfiltrating customer data. A ransom demand was reportedly issued, with threats of public disclosure if payment is not received. #australia
www.hendryadrian.com
April 15, 2026 at 11:00 PM
Ransomware group Insomnia claims to have encrypted systems at United Medical Doctors, a healthcare provider with 70+ locations in Southern California. Patient data may be exposed if ransom isn’t paid. #HealthcareAttack #Ransomware #UnitedStates
Ransom! United Medical Doctors (APR-2026)
Insomnia, a ransomware threat actor, claims to have compromised United Medical Doctors (UMD), a multi-specialty medical-surgical group with 70+ Southern California locations and 40+ specialties. The claim describes encrypted systems and potential exposure or release of patient data unless a ransom is paid. #UnitedStates
www.hendryadrian.com
April 10, 2026 at 9:00 AM
Anubis ransomware targets Signature Healthcare in the US, threatening data encryption and possible exfiltration. The outcome remains uncertain as the countdown continues. #HealthcareAttack #RansomwareUS #UnitedStates
www.hendryadrian.com
April 9, 2026 at 2:46 PM
A cyberattack on Signature Healthcare detected April 6, 2026, caused system outages, ambulance diversions, and treatment delays including chemotherapy cancellations. Experts are investigating and restoring services. #HealthcareAttack #HospitalDisruption
Signature Healthcare Cyberattack Causes Service Disruptions, Treatment Delays
A cyberattack on Signature Healthcare, first detected April 6, 2026, disrupted critical systems at Signature Healthcare and Signature Healthcare Brockton Hospital, forcing downtime procedures, ambulance diversions, and outages that impacted laboratory testing, pharmacy services, and administrative operations. Chemotherapy infusions were temporarily canceled and later phased back in while surgeries and urgent...
www.hendryadrian.com
April 9, 2026 at 1:45 PM
Massachusetts’ Signature Healthcare and Brockton Hospital are diverting ambulances and canceling treatments after a cyberattack disrupted systems. Experts are investigating; no group has claimed responsibility yet. #Massachusetts #HealthcareAttack
Massachusetts hospital turning ambulances away after cyberattack
A cyberattack on Signature Healthcare and Signature Healthcare Brockton Hospital in Massachusetts forced ambulance diversions, activation of downtime procedures, and cancellations such as chemotherapy infusions while core emergency and inpatient services continue. Hospital officials are working with outside experts to investigate and restore systems, no group has claimed responsibility, and industry...
www.hendryadrian.com
April 8, 2026 at 1:45 AM
Signature Healthcare’s Brockton Hospital faced a cyberattack on April 6, 2026, disrupting IT systems. Ambulance diversions and chemotherapy infusions were canceled; retail pharmacies closed. Investigation ongoing. #HealthcareAttack #HospitalDisruption
Brockton Hospital Cyberattack Disrupts Services; Ambulance Diversions and Chemotherapy Infusion Canceled
Signature Healthcare and Brockton Hospital confirmed a cybersecurity incident that disrupted certain IT systems, causing ambulance traffic to be diverted and infusion chemotherapy services to be cancelled on April 6, 2026. The hospital activated offline procedures, closed retail pharmacies, and is working with external partners to investigate and restore operations as quickly as possible. #SignatureHealthcare #BrocktonHospital
www.hendryadrian.com
April 7, 2026 at 4:15 PM
Ransomware in 2025-26 hit healthcare, finance, and manufacturing hard—UMMC’s Epic EHR offline across 35 clinics, BridgePay’s payment network crippled. Multi-extortion and AI tools drive new defenses like D.AMO. #RansomwareTrends #HealthcareAttack
Evolution of Ransomware: Multi-Extortion Ransomware Attacks
Ransomware incidents in 2025–2026 caused major operational disruptions across healthcare, finance, and manufacturing—most notably taking the University of Mississippi Medical Center's Epic EHR offline and crippling BridgePay's payment network. The shift to double- and multi-extortion tactics, the emergence of dozens of new ransomware groups, and AI-enabled tools have made data-neutralizing encryption and process-based access controls like D.AMO critical for blocking attacks and enabling rapid recovery. #UMMC #BridgePay
www.hendryadrian.com
April 3, 2026 at 5:00 PM
The insomnia ransomware group claims to have compromised a major California-based healthcare ecosystem combining clinical care, surgery, research, and workforce development, targeting critical US infrastructure. #HealthcareAttack #Ransomware
Ransom! *****d **d**** ****o** (APR-2026)
The insomnia ransomware group claims to have compromised *****d **d**** ****o**, a California-based healthcare organization that functions as a comprehensive ecosystem, combining clinical care, surgical services, research innovation, and workforce development. The claim frames the attack as targeting the United States #UnitedStates
www.hendryadrian.com
April 2, 2026 at 8:00 PM
Ransomware group qilin claims to have compromised Doctor.com, a US healthcare provider. Details on ransom, encryption, and data leakage remain unconfirmed. #HealthcareAttack #DataBreach #UnitedStates
Ransom! Doctor.com (MAR-2026)
A ransomware claim alleges that the threat actor qilin compromised Doctor.com in the United States. Details are sparse, with no confirmed ransom amount, encryption method, or data leakage claims. #UnitedStates
www.hendryadrian.com
March 29, 2026 at 5:20 PM
Valley Family Health Care, a US community health center with 12 locations, was hit by a ransomware attack from the group Insomnia. The center provides medical, dental, behavioral, and nutrition services. #HealthcareAttack #RansomwareUS #UnitedStates
Ransom! Valley Family Health Care (JAN-2026)
Insomnia claimed a ransomware incident against Valley Family Health Care, a US-based community health center offering medical, dental, behavioral health, and nutrition services. The organization operates 12 locations (including a mobile unit), accepts major insurances, and provides income-based sliding fees to ensure accessible care. #UnitedStates
www.hendryadrian.com
March 19, 2026 at 8:00 AM