BRIEFRansomwarehighP60
ShinyHunters ransomware threatens healthcare firm NovoCure
NovoCure Limited
Detected22 August 2026 · 15:16 UTC
NovoCure, an Israeli medical-device company, appears on ShinyHunters' leak site with a final warning to pay before August 24, 2026. The healthcare sector is critical, and any leak could expose sensitive patient data or intellectual property. This is an active ransomware victim that requires immediate monitoring.
CategoryRansomware
Severityhigh
Priority score60
Detected22 August 2026 · 15:16 UTC
Ransomware● 57
Ransomware RunSomeWares publica a la farmacia Morton LTCThe ransomware group RunSomeWares has listed Morton LTC Pharmacy, an independent family-owned pharmacy in Wisconsin (US healthcare sector), as a victim. The exposure may include patient and pharmacy operational data. This is a fresh victim notice relevant to healthcare and incident-response teams.Ransomware● 43
Ransomware ScarlettGroup ataca el sitio de Yale University PressThe ScarlettGroup ransomware operation published yalebooks.yale.edu, the book retail site of Yale University Press. While it is an education/e-commerce target rather than core university systems, a compromise could expose customer accounts, orders and payment data. Worth monitoring for credential and payment-card leaks.Ransomware● 50
Ransomware Storm publica al proveedor sanitario estadounidense TheraCareStorm ransomware listed TheraCare, a New York-based multi-service healthcare, rehabilitation and education provider serving children and families across the US Northeast. Healthcare ransomware can halt clinical and educational services and expose sensitive patient records. Monitor the incident for data-leak volume and victim-notification obligations.Ransomware● 52
Ransomware Storm golpea a la cooperativa de ambulancias CETAM de CanadáThe Storm ransomware group published CETAM, a Canadian cooperative of over 400 ambulance technicians and paramedics handling nearly 20,000 calls a year. A healthcare ransomware victim of this type can disrupt emergency dispatch and expose patient and employee data. Track the incident for leaked records and downstream fraud risk.Ransomware● 48
Ransomware LockBit publica a la firma legal Consilio (EE.UU.)LockBit5 has listed Consilio, a global legal software and services provider, as a new ransomware victim. Legal-services vendors often hold highly sensitive client and litigation data, making any breach a serious confidentiality and third-party risk. Organizations relying on Consilio or similar providers should assess supply-chain exposure.Ransomware● 60
Ransomware LockBit publica al banco haitiano Capital BankLockBit5 has listed Capital Bank SA, a Haitian retail and online bank, as a ransomware victim. A hit on a national bank can expose customer accounts and loan data and disrupt payments in an already fragile financial environment. Regional financial defenders should monitor for leaked data and follow-on fraud.