CMD Ransomware Hits 5 Healthcare Nonprofits
Statistical Overview
Victim Totals
- This month: 561
- This quarter: 1339
- Year to date: 3965
- Last 24h: 24
Quarterly Breakdown
Q1: 2631 | Q2: 1339 | Q3: 0 | Q4: 0
Ransomware activity continues to accumulate this quarter, with 24 new victims identified in the last 24 hours. This surge is predominantly influenced by groups such as CMD, Akira, APT73, and Qilin.
Introduction
Recent ransomware activity shows 24 new victim disclosures and sustained threat actor activity. Dominant groups included CMD, Akira, APT73, and Qilin, collectively responsible for over two-thirds of the reported incidents. Affected sectors include Healthcare, Nonprofit, Manufacturing, and Technology. Most organizations were targeted within the United States.
Ransomware Summary Table
| # | Group | Victims (24h) | Sample Victims | Geos | Sectors |
|---|---|---|---|---|---|
| 1 | CMD | 5 | Holy Name of Jesus, Houston Eye Associates, Raise the Bottom (+2) | United States, Canada | Nonprofit, Healthcare |
| 2 | APT73 | 4 | Grupopetersen.com.ar, Minsa.com.mx, Tkgm.gov.tr (+1) | Argentina, Mexico | Media & Entertainment, Government / Public Sector |
| 3 | Akira | 4 | Buffalo niagara convention center, Function enterprises, Gitis (+1) | United States, Italy | Construction & Engineering, Hospitality & Travel |
| 4 | Qilin | 4 | Roto immobilien, Semgrep, Snyder packaging (+1) | United States, Austria | Real Estate, Technology / Software |
| 5 | CoinbaseCartel | 2 | Openmind networks new, Pragmatic solutions new | Ireland, Gibraltar | Technology / Software, Telecommunications |
| 6 | DragonForce | 1 | Le pain quotidien us | United States | Hospitality & Travel |
| 7 | Gunra | 1 | Cablematic dos mil slu | Spain | Technology / Software |
| 8 | INC Ransom | 1 | threadinnovations | Canada | Manufacturing |
| 9 | Medusa Locker | 1 | Sgs gmbh demo | Germany | Manufacturing |
| 10 | World Leaks | 1 | Bmj paperpack | Indonesia | Manufacturing |
CMD was the most active ransomware group, impacting five organizations primarily in the Nonprofit and Healthcare sectors, including Holy Name of Jesus and Houston Eye Associates. Other significant actors, including APT73, Akira, and Qilin, each reported four new victims, diversifying their targeting across Media & Entertainment, Government, Construction & Engineering, Hospitality & Travel, Real Estate, and Technology sectors. This broad activity shows ongoing pressure across various industries, with the United States remaining a primary target geography, a trend observed across recent ransomware group activity updates.
Victim Distribution
By Country
- United States: 11
- Canada: 2
- Spain: 1
- Turkey: 1
- Argentina: 1
- Panama: 1
- Mexico: 1
- Italy: 1
- Ireland: 1
- Indonesia: 1
By Industry
- Medical Practices: 2
- Food and Beverage Manufacturing: 2
- Manufacturing: 2
- Electronics and Technology Distribution: 1
- Religious Organization: 1
- Packaging and Containers Manufacturing: 1
- Law Firms & Legal Services: 1
- Hospitality: 1
- Healthcare: 1
- Construction: 1
The concentration of attacks continues to be highest in the United States, representing nearly half of all new victims. Industrially, the threat environment shows a persistent focus on medical practices and the broader manufacturing sector, which points to strategic targeting of both critical services and industrial operations.
Ransomware News
Topline
Recent developments demonstrate persistent ransomware threats across multiple sectors, characterized by significant data exfiltration, service disruptions, and increasing legal ramifications.
Campaigns & Operations
The Ransom Home group claimed responsibility for a cyberattack on Hospital Clínic de Barcelona, demanding $4.5 million and threatening to release 4 TB of patient data, though authorities have stated they will not pay. Separately, Liberty Mutual is facing a federal class-action lawsuit following a data leak attributed to the Everest Group ransomware operation, which allegedly exfiltrated 108 GB of client information affecting over 15,630 individuals. In Japan, Enessance Holdings Co., Ltd. and Hokuyo Co., Ltd. both disclosed ransomware incidents; Enessance confirmed encryption and the exfiltration of approximately 365,000 customer and 2,000 employee records, while Hokuyo reported a system outage that has since been resolved. Austria's Rhomberg Bau Group also experienced an intrusion involving data exfiltration and ransom demands, prompting a police investigation and system segmentation.
Vulnerabilities & TTPs
The Everest Group's operational tactics frequently involve initial access via credential theft, phishing, or exploiting unpatched services. They then move laterally using legitimate administrative tools to blend with normal network traffic. Data exfiltration remains a consistent outcome across these varied incidents, showing its central role in modern ransomware and extortion campaigns.
Analyst Note
These incidents collectively demonstrate the persistent financial and reputational impact of ransomware, with an ongoing emphasis on data exfiltration as a primary means of coercion for threat actors.
Technical Takeaways
- CMD is the most active group, primarily targeting Healthcare and Nonprofit sectors with five confirmed victims.
- The United States remains the most frequently targeted country, accounting for nearly half of all new ransomware victim disclosures.
- Data exfiltration is a prevalent tactic across multiple ransomware incidents, leading to significant financial and legal consequences for victim organizations, as seen in the Liberty Mutual case.
- Beyond Healthcare, groups like Akira (see our ransomware threat update) and Qilin (detailed in our Qilin ransomware threat activity post) continue to diversify their targeting across Construction, Hospitality, Real Estate, and Technology.
- The persistence of ransomware attacks necessitates strong incident response and data protection strategies, given ongoing exfiltration and operational disruption.