DIREWOLF , a ransomware group that emerged in May 2025, has targeted over 100 U.S. healthcare entities, including the National Kidney Registry. They utilize double-extortion tactics by encrypting files and demanding payment for decryption. They have claimed to exfiltrate 253 GB of sensitive data, including donor medical information and transplant recipient records, but their claims remain unverified.
Despite attacking the National Kidney Registry, they state they have not disrupted its operations, which is crucial for timely transplant arrangements. A countdown gives the registry 11 days to respond to negotiate a payment. DataBreaches is awaiting a response from the registry.