The Orova extortion group has listed Cardiology Associates of Port Huron (CAPH), a Michigan cardiology practice with nine locations, as an alleged victim and claims it stole 256,382 files totaling about 496 GB before encrypting some servers. CAPH has not publicly confirmed or denied the reported June 2026 incident. Orova says the practice could restore affected systems from backups and had prepared the alleged data for public release.
A review of a password-protected archive reportedly found apparently authentic patient information affecting roughly 145,846 to 150,380 people, including as many as 124,893 unique Social Security numbers. The purported leak contains protected health information, clinical and radiology records, insurance and claims data, remittance advice, and contact details, creating risks of identity theft, insurance fraud, and targeted scams; if CAPH knew of a breach by June 25, HIPAA notification requirements may apply.

See the actors and campaigns active against you right now.
5 events from the most recent confirmed update back to the earliest known activity.
DataBreaches reported that CAPH appeared to have been breached by the Orova extortion group.
Orova reportedly posted CAPH, a Michigan cardiology practice with nine locations, on its leak site, including screenshots said to show personally identifiable information and protected health information.
Orova told DataBreaches that it breached Cardiology Associates of Port Huron (CAPH) on June 25, 2026, exfiltrated data, and encrypted some servers. CAPH had not publicly confirmed or refuted the alleged incident.
DataBreaches reviewed a password-protected archive and assessed Orova's claims as appearing accurate, while noting it could not verify every record. Its analysis identified up to 150,380 patient records and 124,893 unique Social Security numbers in a backup dated June 14, 2026.
Orova revised its alleged CAPH theft total from 244,215 files totaling 144 GB to 256,382 files totaling about 496 GB, including a claimed 400 GB backup. The group hosted an alleged CAPH archive split into 70 password-protected parts and was preparing to release the password.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
2 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcedatabreaches.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.