CMD Ransomware Hits 5 Healthcare Nonprofits

Statistical Overview

Victim Totals

  • This month: 561
  • This quarter: 1339
  • Year to date: 3965
  • Last 24h: 24

Quarterly Breakdown

Q1: 2631 | Q2: 1339 | Q3: 0 | Q4: 0

Ransomware activity continues to accumulate this quarter, with 24 new victims identified in the last 24 hours. This surge is predominantly influenced by groups such as CMD, Akira, APT73, and Qilin.

Introduction

Recent ransomware activity shows 24 new victim disclosures and sustained threat actor activity. Dominant groups included CMD, Akira, APT73, and Qilin, collectively responsible for over two-thirds of the reported incidents. Affected sectors include Healthcare, Nonprofit, Manufacturing, and Technology. Most organizations were targeted within the United States.

Ransomware Summary Table

#GroupVictims (24h)Sample VictimsGeosSectors
1CMD5Holy Name of Jesus, Houston Eye Associates, Raise the Bottom (+2)United States, CanadaNonprofit, Healthcare
2APT734Grupopetersen.com.ar, Minsa.com.mx, Tkgm.gov.tr (+1)Argentina, MexicoMedia & Entertainment, Government / Public Sector
3Akira4Buffalo niagara convention center, Function enterprises, Gitis (+1)United States, ItalyConstruction & Engineering, Hospitality & Travel
4Qilin4Roto immobilien, Semgrep, Snyder packaging (+1)United States, AustriaReal Estate, Technology / Software
5CoinbaseCartel2Openmind networks new, Pragmatic solutions newIreland, GibraltarTechnology / Software, Telecommunications
6DragonForce1Le pain quotidien usUnited StatesHospitality & Travel
7Gunra1Cablematic dos mil sluSpainTechnology / Software
8INC Ransom1threadinnovationsCanadaManufacturing
9Medusa Locker1Sgs gmbh demoGermanyManufacturing
10World Leaks1Bmj paperpackIndonesiaManufacturing

CMD was the most active ransomware group, impacting five organizations primarily in the Nonprofit and Healthcare sectors, including Holy Name of Jesus and Houston Eye Associates. Other significant actors, including APT73, Akira, and Qilin, each reported four new victims, diversifying their targeting across Media & Entertainment, Government, Construction & Engineering, Hospitality & Travel, Real Estate, and Technology sectors. This broad activity shows ongoing pressure across various industries, with the United States remaining a primary target geography, a trend observed across recent ransomware group activity updates.

Victim Distribution

By Country

  • United States: 11
  • Canada: 2
  • Spain: 1
  • Turkey: 1
  • Argentina: 1
  • Panama: 1
  • Mexico: 1
  • Italy: 1
  • Ireland: 1
  • Indonesia: 1

By Industry

  • Medical Practices: 2
  • Food and Beverage Manufacturing: 2
  • Manufacturing: 2
  • Electronics and Technology Distribution: 1
  • Religious Organization: 1
  • Packaging and Containers Manufacturing: 1
  • Law Firms & Legal Services: 1
  • Hospitality: 1
  • Healthcare: 1
  • Construction: 1

The concentration of attacks continues to be highest in the United States, representing nearly half of all new victims. Industrially, the threat environment shows a persistent focus on medical practices and the broader manufacturing sector, which points to strategic targeting of both critical services and industrial operations.

Ransomware News

Topline

Recent developments demonstrate persistent ransomware threats across multiple sectors, characterized by significant data exfiltration, service disruptions, and increasing legal ramifications.

Campaigns & Operations

The Ransom Home group claimed responsibility for a cyberattack on Hospital Clínic de Barcelona, demanding $4.5 million and threatening to release 4 TB of patient data, though authorities have stated they will not pay. Separately, Liberty Mutual is facing a federal class-action lawsuit following a data leak attributed to the Everest Group ransomware operation, which allegedly exfiltrated 108 GB of client information affecting over 15,630 individuals. In Japan, Enessance Holdings Co., Ltd. and Hokuyo Co., Ltd. both disclosed ransomware incidents; Enessance confirmed encryption and the exfiltration of approximately 365,000 customer and 2,000 employee records, while Hokuyo reported a system outage that has since been resolved. Austria's Rhomberg Bau Group also experienced an intrusion involving data exfiltration and ransom demands, prompting a police investigation and system segmentation.

Vulnerabilities & TTPs

The Everest Group's operational tactics frequently involve initial access via credential theft, phishing, or exploiting unpatched services. They then move laterally using legitimate administrative tools to blend with normal network traffic. Data exfiltration remains a consistent outcome across these varied incidents, showing its central role in modern ransomware and extortion campaigns.

Analyst Note

These incidents collectively demonstrate the persistent financial and reputational impact of ransomware, with an ongoing emphasis on data exfiltration as a primary means of coercion for threat actors.

Technical Takeaways

  • CMD is the most active group, primarily targeting Healthcare and Nonprofit sectors with five confirmed victims.
  • The United States remains the most frequently targeted country, accounting for nearly half of all new ransomware victim disclosures.
  • Data exfiltration is a prevalent tactic across multiple ransomware incidents, leading to significant financial and legal consequences for victim organizations, as seen in the Liberty Mutual case.
  • Beyond Healthcare, groups like Akira (see our ransomware threat update) and Qilin (detailed in our Qilin ransomware threat activity post) continue to diversify their targeting across Construction, Hospitality, Real Estate, and Technology.
  • The persistence of ransomware attacks necessitates strong incident response and data protection strategies, given ongoing exfiltration and operational disruption.