Lockbit5 lists Tennessee Medical Association after claimed intrusion

Lockbit5 claims an intrusion into the Tennessee Medical Association, and attorneys have opened a probe.

MedRisk Staff
By
2 Min Read

The Lockbit5 ransomware group has posted the Tennessee Medical Association on its leak site, claiming an intrusion into the nonprofit that represents physicians across the state.

The claim, dated August 28 on ransomware.live, estimates the attack occurred the day before. The association’s website domain, tnmed.org, is the named victim. ClassAction.org opened a lawsuit investigation the same day, asking current and former TMA members and staff who believe their information may be exposed to come forward. No scope, affected-count, or data-type details have been published, and the association has not confirmed the incident publicly.

The association’s day-to-day work spans continuing medical education, practice toolkits, and statehouse lobbying on behalf of doctors. Member rosters commonly hold contact details, credentials, and billing information, so the exposed categories will depend on what the organization kept on file.

Physician practices that hold TMA memberships face a phishing angle: groups that steal membership rolls often reuse them to target individuals with credential-harvesting messages. Staff should treat any TMA-branded email demanding login details or payment as suspect and forward it to IT before clicking.

The listing is one more reminder that medical associations and professional bodies sit in the same threat path as hospitals and clinics, even when they never touch a patient record directly.

Share This Article