Ransomware Group ‘Direwolf’ Claims Attack on National Kidney Registry

A ransomware group calling itself Direwolf claims to have obtained data from National Kidney Registry, according to a listing on the group’s dark web leak site dated August 25, 2026. This claim was tracked by ransomware.live, a security research platform that monitors ransomware groups’ public leak sites. At this time, National Kidney Registry has not confirmed the incident, and no regulator has verified the group’s assertion. This should be treated as an unverified claim made by a criminal group, not an established fact.

What we know — and don’t
  • A group identifying itself as Direwolf listed National Kidney Registry on its leak site with a claimed date of August 25, 2026.
  • National Kidney Registry operates in the healthcare space, connecting living kidney donors with patients in need of transplants.
  • The specific types of data the group claims to have obtained have not been disclosed in the listing and have not been independently confirmed.
  • No public statement from National Kidney Registry acknowledging or denying the claim is currently available.
  • No regulatory filing or breach notification tied to this claim has been identified as of this writing.
What should you do if you have an account with this company?
  • Change your password for any account associated with National Kidney Registry, and avoid reusing that password elsewhere.
  • Enable two-factor authentication (2FA) wherever it is offered, particularly on email and financial accounts.
  • Be cautious of unexpected emails, texts, or phone calls referencing National Kidney Registry, medical records, or donor registration — these could be phishing attempts trying to exploit uncertainty around this claim.
  • Monitor your financial statements and credit reports for unfamiliar activity, especially if the organization holds sensitive personal or health-related information about you.
  • Consider using a service like a service like Aura or LifeLock for ongoing identity monitoring, which can alert you if your personal information appears in places it shouldn’t.
  • Keep an eye on official communications directly from National Kidney Registry rather than relying solely on third-party reports.

BreachLetter will update this page if National Kidney Registry confirms this incident, if new details emerge from the group’s claims, or if the matter is officially reported to regulators.

Leave a Comment