NocturnLock, a ransomware operation tracked by Threxar since early 2026, has claimed responsibility for an attack against Meridian Health Systems (fictional), a regional healthcare provider. The group published a post to their Tor-hosted leak site alleging that 14GB of patient administrative data was exfiltrated prior to encryption.
What Was Published
The leak site post includes a file tree preview and a sample directory listing. Based on the listing structure, the data appears to include:
- Patient scheduling and appointment records
- Insurance claim metadata
- Internal HR documents (staff names, roles, department assignments)
- Financial reporting files
No clinical records (lab results, imaging, prescriptions) appear in the previewed listing, though this cannot be confirmed without full access.
NocturnLock Background
NocturnLock has been active since approximately Q1 2026. Threxar has tracked nine claimed victims to date, primarily in healthcare, education, and regional government. The group operates a classic double-extortion model: encrypt, exfiltrate, then threaten public disclosure.
Technical indicators suggest NocturnLock may share a common toolset with the defunct "IronVault" operation, including use of a customised version of the open-source privilege escalation tool PrintSpooler.
Recommended Actions
- Healthcare providers should audit VPN and remote access configurations
- Review any exposures of RDP to the public internet
- Ensure offline/immutable backup copies exist and are tested