LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › National Kidney Registry Listed by Direwolf Ransomware Group

HIGH severityUnverified claimHow we verify

National Kidney Registry Listed by Direwolf Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·August 25, 2026

SourceLeak-site claim data adapted from RansomLook.io, used under CC BY 4.0.

National Kidney Registry Listed by Direwolf Ransomware Group

Reported August 25, 2026.

HIGH
Severity
August 25, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

National Kidney Registry was listed by the Direwolf ransomware group on August 25, 2026, after an undisclosed number of people had their personal data exposed. Individuals who may have been affected should check the registry’s notices and consider protective steps such as monitoring accounts and changing passwords.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

In a ransomware ecosystem where leak-site postings are used as pressure tactics as often as they reflect verified theft, a new listing has drawn attention to a U.S. nonprofit that coordinates living kidney donation. On August 25, 2026, the group known as Direwolf listed National Kidney Registry on its leak site and claimed to have taken internal data. The scale of any intrusion, the method, and what—if anything—was copied remain undisclosed in public reporting tied to that listing.

National Kidney Registry has not publicly confirmed the claim as of writing. A leak-site entry is an accusation by an extortion crew, not an independent finding by the organization, a regulator, or a breach index. For patients, donors, families, and partner clinics, the practical question is conditional: what to watch for if sensitive material associated with this kind of work were ever misused, and how to respond without treating an unverified claim as settled fact.

What the listing says

According to the listing, National Kidney Registry appears on the Direwolf ransomware leak site. The group claims to have stolen internal data. Public detail attached to that claim is thin. The number of people potentially affected is unknown. Specific data types named as exposed are not disclosed. Timing beyond the August 25, 2026 report date, technical method, ransom demands, and any proof package contents are not described in the facts available for this summary.

Nothing in the listing, as reported here, has been corroborated by the organization in a public statement included in these facts. Readers should treat the post as what it is: a named group’s assertion on a site designed to coerce payment through threatened publication, not a completed forensic account.

The group behind it: Direwolf

Direwolf is known in open reporting as a ransomware and data-extortion actor that follows a pattern common to many contemporary crews: encrypt or disrupt systems where it can, exfiltrate material it claims to hold, and threaten leak-site publication to increase pressure. Groups in this category often post victim names, countdown-style messaging, and sample files—sometimes accurate, sometimes inflated, and occasionally recycled or wrong—to force negotiation.

Well-documented public patterns for such actors include double-extortion framing (disruption plus alleged data theft), use of affiliate-style operations in the broader ransomware economy, and reliance on leak sites as both distribution channel and advertising. Those general traits do not prove what happened in any single case. For National Kidney Registry, the only incident-specific assertion in the available facts is that Direwolf listed the organization and claims to have stolen internal data. No further quotes, file counts, or technical indicators unique to this listing are provided here.

About National Kidney Registry

National Kidney Registry is a U.S. organization focused on facilitating living kidney donation and paired exchange—matching donors and recipients across chains so more transplants can proceed when a direct donor-recipient pair is incompatible. Work of this kind sits at the intersection of healthcare coordination, nonprofit operations, and highly sensitive personal circumstances: medical suitability, timing of surgery, family relationships, and trust among hospitals and transplant centers.

Organizations in this sector typically maintain records needed to run matching programs, communicate with donors and recipients, and coordinate with clinical partners. A credible compromise in that environment would matter because the underlying activity involves health status, identity, and life-altering medical decisions. That sector context explains public interest in any serious claim; it does not establish that a breach occurred or that any particular system failed. The Direwolf listing is still only a claim, and the company has not publicly stated the incident as of writing.

The information in question

The facts state that data types named as exposed are not disclosed. The group’s marketing language on a leak site is not an inventory. It is therefore not possible, from the material given, to assert which files, databases, or categories of personal information—if any—were taken.

If internal material from an organization like National Kidney Registry were ever copied, firms and nonprofits in living-donation and transplant coordination typically hold some mix of the following kinds of information (stated here as sector norms, not as confirmed contents of this claim): identity and contact details for donors, recipients, and family contacts; clinical and compatibility-related data used in matching; communications with transplant centers; scheduling and logistics records; and ordinary business records such as staff directories, contracts, or finance files. Whether any of that was involved here is unconfirmed. People who have interacted with the registry should not assume their records are in criminal hands solely because of a leak-site post.

Why it matters

Extortion listings aimed at healthcare-adjacent nonprofits raise stakes even when unverified, because the possible subject matter is intimate and hard to change. If personal or medical-adjacent data were misused, affected individuals could face phishing that impersonates transplant coordinators, pressure scams that reference donation or surgery, identity fraud, or unwanted exposure of health situations they shared only for care. Partner hospitals and clinics could see social-engineering attempts that cite forged “internal” details. The organization itself could face operational distraction, reputational strain, and the cost of investigation—again, contingent on whether the claim has substance.

At the same time, leak-site economics reward dramatic claims. Listings can exaggerate scope, blur old incidents with new ones, or name victims prematurely. What a Direwolf listing establishes is that the group chose to name National Kidney Registry and to allege theft of internal data on or about the reported date. What it does not establish is confirmation, a headcount, a data inventory, or any judgment about the organization’s security program. Public detail remains limited; treating accusation as proof helps the extortion narrative more than it helps people decide what to do.

What to do now

Response should stay practical and conditional. If you are a donor, recipient, family member, or staff contact who has shared information with National Kidney Registry or similar programs, consider the following steps while the listing remains unconfirmed by the organization:

Readers who want a concrete next check can run a free exposure scan of their email to see whether that address has already appeared in known breach datasets unrelated to this claim. Continue to rely on official statements from National Kidney Registry and recognized public authorities for confirmation; until those exist, Direwolf’s listing should be read as an unverified extortion-site claim dated in reporting to August 25, 2026, not as a finished account of stolen records.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyNational Kidney Registry security record
84/100
DoxxScan™ · Low doxx risk
B- 76Above-average record

1 reported incident on record.

See National Kidney Registry’s full breach history →

More recent breaches

Studio Legale ESE Listed by Direwolf Ransomware GroupAugust 25, 2026PayUp Listed by Direwolf Ransomware GroupAugust 19, 2026Photon Health, Inc. Listed by Direwolf Ransomware GroupAugust 19, 2026InfoFlo CRM Listed by Direwolf Ransomware GroupAugust 19, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the National Kidney Registry Listed by Direwolf Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by direwolf — unverified claim, pending independent verification. Leak-site claim data adapted from RansomLook.io, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram