NetRunnerPR is a little-documented threat actor name associated with an alleged 2026 intrusion and data-extortion claim involving Nippon Medical School Musashi Kosugi Hospital in Japan. The actor publicly claimed to have exfiltrated more than 131,000 patient records and threatened a staged public release of additional records unless unspecified demands were met. The claimed dataset was described as containing personally identifiable and patient-related information, and the actor reportedly used pressure tactics that included references to senior hospital leadership and family members. Available reporting supports only a narrow, low-confidence profile. NetRunnerPR appeared as a relatively new underground-forum persona with limited activity history and no publicly documented track record linking it to established ransomware operations or previously confirmed breaches. The alleged incident had not been officially confirmed at the time of reporting, and the authenticity, completeness, recency, and provenance of the purported data remained unverified. No evidence confirmed file encryption or a ransomware deployment in this case. Based on the observed behavior, NetRunnerPR is best characterized as an extortion-oriented actor or persona associated with alleged data theft and threatened disclosure rather than a confirmed ransomware operator. High-confidence observed behavior is limited to claimed exfiltration and coercive leak threats against a healthcare victim in Japan.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Data-leak actor (forum persona) claiming breaches and advertising/teasing stolen datasets; activity described as financially motivated data-leak operations (claim unverified in the report).
Claimed responsibility for an alleged cyberattack against a Japanese hospital, asserting theft of 131,135 patient records and threatening to publicly release an additional 20,000 records as extortion pressure. The claim remains unverified, and no confirmed history links the actor to major ransomware operations or prior confirmed breaches.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.