National Kidney Registry listed by DireWolf ransomware group
The DireWolf extortion group claimed to have stolen roughly 253 GB of highly sensitive data — including donor and transplant-recipient medical records — from the National Kidney Registry, a U.S. nonprofit that facilitates living-donor kidney transplants.
- Victim
- National Kidney Registry
On 25 August 2026, the extortion group DireWolf claimed responsibility for a cyberattack against the National Kidney Registry (NKR), a leading U.S. nonprofit that coordinates living-donor kidney transplants and paired-exchange programs. The group listed NKR on its leak site, asserting it had exfiltrated roughly 253 GB of data comprising about 180,000 files across eight datasets, including donor medical information and transplant-recipient records.
According to the group's claims, the stolen material included Social Security numbers, dates of birth, full medical histories, imaging, HLA (tissue-typing) data, financial proofs and personal contact details — categories subject to HIPAA and organ-allocation data-protection rules. DireWolf told researchers its operation involved data theft rather than disruption of NKR's IT systems. At disclosure, no sample files or screenshots had been published, and none of the claims had been independently confirmed.
What happened
The registry occupies a uniquely sensitive position: it matches living donors with recipients nationwide, meaning its records tie individuals' identities directly to medical, immunological and financial data. Because the alleged theft did not disrupt operations, the primary risk is the exposure and potential publication of that data — a classic data-theft-only extortion play designed to pressure a mission-driven nonprofit into paying.
Why it matters
An alleged breach of an organ-transplant registry raises acute privacy and safety concerns, given the irreplaceable nature of the medical and immunological data involved. The case highlights how nonprofits handling critical health functions — often with constrained security resources — have become targets for extortion groups that weaponize the sensitivity of the data itself.
Timeline
The DireWolf ransomware group claims responsibility for an attack on the National Kidney Registry.
Reporting details DireWolf's claim of 253 GB across roughly 180,000 files spanning donor and recipient records.
Sources
- databreaches.nethttps://databreaches.net/2026/08/26/national-kidney-registry-allegedly-hacked-by-direwolf-ransomware-group/
- socradar.iohttps://socradar.io/blog/data-breach/national-kidney-registry-direwolf-ransomware-2026/
- ransomware.databreachtoday.comhttps://ransomware.databreachtoday.com/kidney-transplant-registry-hack-raises-safety-concerns-a-32672