Ransomware victim disclosure
← All victimsAliveCor, Inc.
Claimed by Direwolf · listed 7 days ago
Status timeline
- ListedAug 10, 2026
- Data leakeddate unknown
At a glance
- Group
- Direwolf
- Status
- Data leaked
- Country
- United States
- Sector
- Healthcare
- Listed on leak site
- Aug 10, 2026
About the victim
AI dossier — public-source company profileAliveCor, Inc. develops AI-enabled, machine learning-powered ECG (electrocardiogram) sensors and digital health platforms for remote cardiac monitoring. The company provides personal ECG devices (Kardia product line), enterprise solutions for health systems, clinical trial monitoring for biopharma, and cardiac health management services for payers and employers. They serve consumers, healthcare providers, and institutional customers across 40+ countries.
- Industry
- Medical Device & Artificial Intelligence
Attack summary
Severity: critical — AliveCor handles sensitive health data including ECG readings and patient medical records at scale (3M+ lifetime users). The post explicitly flags GDPR-restricted data, indicating confirmed exfiltration of regulated personal data from EU residents. Healthcare data breaches involving cardiac/medical information represent critical regulatory and patient safety risk.The direwolf group claims to have exfiltrated data from AliveCor. The leak post indicates GDPR-restricted data is involved, suggesting personal data of EU residents or European operations. No specific operational disruption or encryption claim is stated in the post.
Data the group says was taken
AI dossier — extracted from the leak post- Personal health information (ECG data)
- Patient identifiers
- Clinical records
- Healthcare provider data
- Potentially PII of EU residents (GDPR-flagged)
What the group claims
medical device and artificial intelligence
The leak post
captured from the group's site```
{"article":{"id":71,"title":"AliveCor, Inc.","content":"","summary":"{\"company_name\":\"AliveCor, Inc.\",\"company_website\":\"https://alivecor.com\",\"industry\":\"medical device and artificial intelligence\",\"gdpr_restricted\":true,\"data_size\":\"\"}","country":"US","file_browser_url":"","data_types":"4,11,16,20,22,25,27,29,30","countdown_end":"2026-08-31T23:59:00Z","status":"","view_count":0,"publish_time":"2026-08-10T18:26:14.489475764Z","created_at":"2026-08-10T18:26:14.489476154Z","updated_at":"2026-08-10T18:26:14.489476154Z"}}
```Sources
Source
Indexed 7 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

