Direwolf adds medical billing firm and cancer support startup to leak list

The Direwolf gang listed medical billing firm PayrHealth and cancer mental health startup Colla Health on the same day.

MedRisk Staff
By
2 Min Read

The Direwolf ransomware gang listed two healthcare companies on its leak site on the same day, according to ransomware trackers that monitor extortion claims.

PayrHealth, a medical billing and healthcare contracting firm that manages revenue cycles for physician practices, appeared in listings logged on August 15, 2026. So did Colla Health, which provides mental health services for cancer patients and works with cancer centers and community oncology practices nationwide. Both claims are unconfirmed, and neither company has issued a public statement.

Ransomware.live logged the pair with attack dates estimated the same day, and RansomLook’s Direwolf group page carries both entries dated August 15. Hudson Rock infostealer telemetry tied to PayrHealth’s domain lists six third-party employee credentials in stolen-log collections, a signal that credential theft may be part of the exposure chain.

Direwolf has kept healthcare in its sights through August, previously claiming ECG device maker AliveCor, Spain’s Quironsalud hospital group, telehealth platform Leafwell, and nurse staffing firm Health Carousel. The group typically demands payment to avoid publishing stolen files.

For revenue cycle firms and digital health startups, the listings are a reminder that even small patient-adjacent data sets are targets. Healthcare CISOs should pressure business associates that handle claims, billing, or clinical support data to verify their own defenses, since a vendor leak-site listing can quickly turn into a mass notification event.

Share This Article