PrivacySignal
Breach

National Kidney Registry allegedly hacked by DireWolf ransomware group

DataBreaches.net · · International · Data Breaches

Since its emergence in May 2025, DireWolf has attacked several U.S. healthcare entities, as listed among its more than 100 targets on its dedicated leak site. As early analysts reporting on the group have noted, DireWolf encrypts victims’ files as part of their double-extortion attacks. Their “About” statement describes them as financially motivated: We are... Source

Who should care: Cybersecurity · Privacy officers · Administrators

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

Related stories

Breach
DataBreaches.net · · International

A recommendation from the Saskatchewan Information and Privacy Commissioner caught our eye

A data breach at Autism Services of Saskatoon exposed the personal information of more than 2,000 people. Saskatchewan's Information and Privacy Commissioner reviewed the incident and found the organization responded appropriately, notifying those affected and improving its security systems.

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · Policy

#breach#privacy Read original →
Breach
BleepingComputer · · International

LACMA data breach last year exposed social security and medical data

The Los Angeles County Museum of Art disclosed that a data breach occurring last year exposed sensitive personal information belonging to customers and employees, including Social Security numbers and medical data.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance

#breach#healthcare Read original →
Breach
DataBreaches.net · · International

‘Close Enough’ Data Breach Notifications Create Exposure

A summary judgment ruling against a telecom company in a state regulatory lawsuit illustrates how vague or approximate data breach notifications can create legal liability. The case suggests that companies falling short of precise technical disclosure standards may face enforcement consequences beyond the breach itself.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance

#breach#enforcement#regulation Read original →
Breach
DataBreaches.net · · International

Seoul National University Hospital skips cybersecurity disclosure for years despite breach affecting 830,000

Seoul National University Hospital did not file mandatory cybersecurity disclosures for years, even after a breach that affected 830,000 people. An investigation revealed the hospital had been operating under an exemption from the standard reporting requirements that apply to other large hospitals.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance

#breach#enforcement Read original →
Breach
BleepingComputer · · International

Hospital operator Nutex Health says data stolen in cyberattack

Nutex Health, a hospital operator and healthcare services provider, is investigating a cyberattack in which an unauthorized party removed data from its systems. The company has not disclosed what types of information were taken or how many people may be affected.

Who should care: Cybersecurity · Privacy officers · Administrators