Ransomware victim disclosure
← All victimsLeafwell
Claimed by Direwolf · listed 7 days ago
Status timeline
- ListedAug 11, 2026
- Data leakeddate unknown
At a glance
- Group
- Direwolf
- Status
- Data leaked
- Country
- United States
- Sector
- Healthcare
- Listed on leak site
- Aug 11, 2026
About the victim
AI dossier — public-source company profileLeafwell is an online telemedicine platform that connects patients with licensed physicians to obtain medical marijuana certifications. The service operates across multiple US states and claims over 1 million monthly users, offering rapid online approval for medical cannabis cards.
- Industry
- Telemedicine & Medical Cannabis Certification
Attack summary
Severity: critical — Healthcare sector company with patient personal and medical data at scale (1M+ monthly users). Medical records and health condition information constitute regulated sensitive data (HIPAA-protected in the US). Confirmed data publication by threat actor.The direwolf group claims to have compromised Leafwell and published data. The group categorizes the victim as 'Hospitals & Physicians Clinics,' indicating healthcare sector targeting.
Data the group says was taken
AI dossier — extracted from the leak post- Patient medical records
- Personal health information
- Certification/application data
- User account information
What the group claims
Hospitals & Physicians Clinics
Sources
Source
Indexed 7 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

