Ransomware Group ‘Direwolf’ Claims Attack on Photon Health, Inc.

A ransomware group calling itself Direwolf claims to have carried out an attack on Photon Health, Inc., with the claim appearing on the group’s dark-web leak site on or around August 19, 2026. This listing has been tracked by ransomware.live, a security research platform that monitors ransomware groups’ public leak sites. It is important to stress that this is an unverified claim made by a criminal group seeking publicity and leverage — Photon Health, Inc. has not confirmed any breach, and no regulator or independent investigator has verified the group’s assertion at this time.

What we know — and don’t
  • A group calling itself Direwolf posted a claim referencing Photon Health, Inc. on its leak site, dated approximately August 19, 2026.
  • Photon Health, Inc. operates in the healthcare sector, which often involves sensitive patient and operational data, though this does not confirm what, if anything, was actually accessed.
  • The specific types of data the group claims to have obtained — such as patient records, financial information, or employee data — have not been disclosed or confirmed by any party.
  • Photon Health, Inc. has not issued a public statement confirming or denying the claim as of this writing.
  • No regulatory filing or breach notification tied to this claim has been identified at this time.
What should you do if you have an account with this company?
  • Change your password for any account associated with Photon Health, Inc., and avoid reusing that password on other sites.
  • Enable two-factor authentication (2FA) wherever it is offered, particularly for accounts tied to health or financial information.
  • Be cautious of unexpected emails, texts, or calls referencing Photon Health, Inc., as ransomware claims are often followed by phishing attempts that exploit public fear over a possible breach.
  • Review recent account activity and statements for anything unfamiliar, especially if the account involves insurance, billing, or medical records.
  • Consider signing up for identity monitoring, such as a service like Aura or LifeLock, so you can be alerted quickly if your personal information turns up somewhere it shouldn’t.
  • Keep any correspondence from Photon Health, Inc. regarding this matter, in case it becomes relevant to your own recordkeeping later.

BreachLetter will update this page if Photon Health, Inc. confirms this incident, issues a public statement, or if the matter is officially reported to regulators.

Leave a Comment