The Orova ransomware group has claimed a widening set of victims across the United States, Hong Kong, and the UK, hitting organizations in healthcare, manufacturing, financial services, professional services, religious institutions, community associations, and agriculture. Reported victims include Integrated Site Management, Tat Fung Textile Co., Ltd., JK Capital Management Limited, Global Friction Products, Conceptual Designs, Stonecrest POA, Stoneybrook West Master Association, St Theresa Catholic Church, Country Oaks Veterinary Clinic, Magnolia Dental, Woodside Ranch, David King Architect, First Baptist Church of Belleview, Gemstone UK, and Hilliard’s Air Conditioning & Heating. One notable claim involved FixIT Tek, where Orova allegedly compromised a Syncro MSP panel and stole client data, raising the prospect of downstream exposure through a managed service provider environment.
Separate reporting indicates Orova is operating as a newly observed ransomware-as-a-service group and may be a branch of a previously vanished operation. In healthcare, the group has listed Wisdom Oral Surgery, Magnolia Dental, and Cardiology Associates of Port Huron on its leak site; for the Michigan cardiology practice, Orova claimed to have stolen more than 244,000 files totaling 144 GB after a June intrusion and published screenshots that allegedly exposed PII, PHI, insurance records, and at least one full Social Security number. The breadth of victims and the publication of sensitive medical data suggest Orova is combining encryption and data-theft extortion while rapidly building a leak-site presence around smaller and midsize organizations.

TTPs, infrastructure, and targeting history in one profile.
37 events from the most recent confirmed update back to the earliest known activity.
The First Baptist Church of Belleview incident was listed as discovered on August 6, 2026 at 11:20 UTC.
The Hilliard's Air Conditioning & Heating Inc. incident was listed as discovered on August 6, 2026 at 10:51 UTC.
The Gemstone UK incident was listed as discovered on August 6, 2026 at 10:50 UTC.
The St Theresa Catholic Church incident was listed as discovered on August 6, 2026 at 09:52 UTC.
The Stoneybrook West Master Association, Inc. incident was listed as discovered on August 6, 2026 at 09:51 UTC.
The Stonecrest POA incident was listed as discovered on August 6, 2026 at 09:50 UTC.
The Magnolia Dental incident was reported as discovered on August 6, 2026 at 09:22 UTC.
The Country Oaks Veterinary Clinic incident was listed as discovered on August 6, 2026 at 09:22 UTC.
The David King Architect incident was listed as discovered on August 6, 2026 at 09:21 UTC.
The Woodside Ranch incident was listed as discovered on August 6, 2026 at 09:20 UTC.
First Baptist Church of Belleview was reported as the victim of a ransomware attack attributed to Orova. The breach date was listed as August 6, 2026.
Hilliard's Air Conditioning & Heating Inc. was reported as the victim of a ransomware attack attributed to Orova. The breach was dated August 6, 2026.
Gemstone UK was reported as the target of a ransomware incident attributed to Orova. The breach date was listed as August 6, 2026.
St Theresa Catholic Church was identified as the victim of a ransomware attack attributed to Orova. The breach was dated August 6, 2026.
Stoneybrook West Master Association, Inc. was identified as the victim of a ransomware attack attributed to Orova. The breach was dated August 6, 2026.
Stonecrest POA was identified as the victim of a ransomware attack attributed to Orova. The breach date was listed as August 6, 2026.
Magnolia Dental was identified as the victim of a ransomware attack attributed to Orova. The breach date was reported as August 6, 2026.
Country Oaks Veterinary Clinic was reported as the victim of a ransomware attack attributed to Orova. The breach date was listed as August 6, 2026.
David King Architect was identified as the victim of a ransomware attack attributed to Orova. The breach date was listed as August 6, 2026.
Woodside Ranch was reported as the victim of a ransomware attack attributed to Orova. The breach date was listed as August 6, 2026.
The FixIT Tek incident was recorded as discovered on August 5, 2026 at 07:21 UTC.
FixIT Tek was reported as the victim of a ransomware attack attributed to Orova. The report said the company's Syncro MSP panel was hacked and a large amount of client data was stolen from its network.
The Conceptual Designs, Inc. ransomware incident was listed as discovered on August 4, 2026 at 12:20 UTC.
The Global Friction Products, Inc. ransomware incident was reported as discovered on August 4, 2026 at 12:19 UTC.
The JK Capital Management Limited incident was reported as discovered on August 4, 2026 at 12:20 UTC.
The Tat Fung Textile Co., Ltd. ransomware incident was listed as discovered on August 4, 2026 at 12:21 UTC.
The Integrated Site Management ransomware incident was listed as discovered on August 4, 2026 at 12:21 UTC.
Conceptual Designs, Inc. was identified as the victim of a ransomware attack attributed to Orova. The breach was dated August 3, 2026.
Global Friction Products, Inc. was reported as the victim of a ransomware attack attributed to Orova. The breach was dated August 3, 2026.
JK Capital Management Limited was identified as the victim of a ransomware attack attributed to Orova. The reported breach date was August 3, 2026.
Integrated Site Management was reported as the victim of a ransomware attack and data breach attributed to Orova. The breach date was listed as August 2, 2026.
Tat Fung Textile Co., Ltd. was reported as the victim of a ransomware attack attributed to Orova. The breach date was listed as August 1, 2026.
DataBreaches reported that Orova added Cardiology Associates of Port Huron to its leak site on July 10, 2026. The listing claimed 244,215 files totaling 144 GB were stolen and included eight screenshots as proof.
DataBreaches reported that Wisdom Oral Surgery appears to have been added to Orova's dark web leak site on July 3, 2026. The listing claimed 20,308 files totaling 29.6 GB were taken.
According to Orova's spokesperson, the group compromised Cardiology Associates of Port Huron on June 25, 2026, stole data, and encrypted some servers. The group claimed the victim had cloud backups available for restoration.
DataBreaches reported that Cardiology Associates of Port Huron had not publicly responded to inquiries despite alleged theft of patient data. Malware News repeated that reporting and said the practice remained silent at the time of publication.
DataBreaches reported that an Orova spokesperson described the group as a startup ransomware-as-a-service operation and a branch of another group that had disappeared earlier. The article also said Orova had listed dozens of victims since early May and targeted medical entities, churches, and non-profits.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
18 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcedatabreaches.net
Open sourcehookphish.com
Open sourcehookphish.com
Open sourcehookphish.com
Open sourcehookphish.com
Open sourcehookphish.com
Open sourcehookphish.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.