The DireWolf ransomware group has allegedly compromised the U.S. National Kidney Registry and listed the nonprofit on its leak site, claiming to have exfiltrated 253 GB of data across about 180,000 files. The purported haul includes donor and recipient medical records and internal documents; however, the claim remains unverified because the group has not released samples or screenshots. DireWolf reportedly said it did not disrupt registry operations and set an alleged 11-day deadline for the organization to enter payment negotiations.
A disruption to transplant coordination could affect tissue matching, laboratory work, scheduling, logistics, and communications, potentially delaying care, increasing the chance of errors, and endangering patients during a prolonged outage. Stolen transplant data could also support persistent fraud and extortion. Health-sector organizations should prioritize strong identity and access management, network segmentation, tested isolated backups, and incident-response exercises that include executive and clinical leadership.

TTPs, infrastructure, and targeting history in one profile.
2 events from the most recent confirmed update back to the earliest known activity.
DireWolf emerged as a financially motivated ransomware group.
DireWolf listed the U.S. National Kidney Registry on its leak site and alleged that it exfiltrated 253 GB of data across roughly 180,000 files, including donor and transplant-recipient records. The claims had not been independently verified, and the group provided no samples or screenshots.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.