The Direwolf ransomware gang has posted medical device maker AliveCor on its dark web leak site, threat trackers reported on August 10.
AliveCor builds the KardiaMobile series of pocket-sized ECG recorders, which pair with a smartphone app that flags possible heart rhythm abnormalities for users and their physicians. The entry appeared on the leak site at 18:58 UTC on August 10, per HookPhish and ransomware.live, both of which logged the victim as a US-based medical device and AI company. Neither the listing nor AliveCor itself has said what information the group claims to have taken, and the company has not acknowledged a breach.
Direwolf is a relatively new operation, with researchers at AhnLab dating its first public victim disclosures to May 2025 and Trustwave documenting its custom Golang encryptor. Its August 10 healthcare push also included Spain’s Quironsalud hospital group and US staffing firm Health Carousel, suggesting the gang is rotating through care-sector targets.
The claim remains unverified, and ransomware groups routinely inflate or fabricate victim lists to pressure companies into paying. Device manufacturers are an attractive target because they hold clinical data, research records, and supply chain information for the hospitals that use their products. Healthcare organizations that rely on AliveCor equipment should watch for supply chain notifications and treat any vendor communications about credential resets with suspicion.
