National Kidney Registry, a nonprofit organization that coordinates kidney paired-donation transplants across a nationwide network of transplant centers, has reportedly been targeted in a ransomware attack. Reports indicate that donors, transplant recipients, applicants, and staff connected to the registry may have had personal and health information exposed as a result. Organizations that are trusted with sensitive medical and personal data have a responsibility to keep that information secure, and when that trust is broken, those affected deserve to know what happened and what is being done about it.
National Kidney Registry’s Data Breach Investigation
According to an August 25, 2026 post on the dark web security tracking site Ransomware.live, the hacker group Dire Wolf claimed responsibility for the attack and reported exfiltrating approximately 253 gigabytes of data from National Kidney Registry. A separate dark web monitoring service, Breachsense, similarly reported that Dire Wolf claimed to be behind the intrusion. As of this writing, National Kidney Registry has not publicly confirmed the incident, and no information has been made available about the specific scope of the alleged breach or how many individuals may be affected.
Ransomware groups that publish claims on leak sites typically use these postings as leverage to pressure a victim organization into paying a ransom, and a leak-site listing alone is not independent confirmation that a breach occurred or that any particular category of data was actually taken. Even so, incidents like this are taken seriously by regulators and by the individuals whose information may be implicated, because healthcare and nonprofit organizations that manage transplant coordination hold uniquely sensitive records, including details about a person’s medical history and their relationship to an active or pending organ donation.
Healthcare-adjacent organizations, including hospitals, medical registries, and coordination nonprofits, have increasingly become targets for ransomware groups in recent years. These organizations often maintain large volumes of highly sensitive personal and health information while relying on interconnected networks of hospitals, laboratories, and outside vendors, any one of which can present an opportunity for attackers to gain access. Once inside a network, ransomware actors frequently combine data theft with extortion, threatening to publish stolen files unless a ransom is paid, which is consistent with the pattern reported in connection with this incident.
When an organization experiences a suspected breach, state and federal notification laws generally require that affected individuals be notified within a specific window once the scope of the incident is understood, though the exact timeline can vary depending on the type of data involved and the states where affected individuals reside. Investigations of this kind typically involve outside cybersecurity specialists working to determine how the attackers gained access, what systems were affected, and which records may have been viewed or copied, a process that can take weeks or longer to complete even after a breach is first suspected.
The categories of information reportedly at risk in this incident, including full names, contact details, and health and donor-matching records, are the kind of information that can be misused for medical identity theft or targeted phishing schemes. Medical identity theft in particular can be difficult to detect, since fraudulent claims filed using a victim’s stolen health information may not surface until an insurer or provider flags unusual activity, and correcting a compromised medical record can be a lengthy process once it happens.
When Did This Breach Occur?
Dire Wolf’s claim regarding National Kidney Registry surfaced publicly on August 25, 2026, and the group indicated the underlying intrusion occurred around the same date. National Kidney Registry has not published its own account of when the incident began or when it was first discovered internally, and no official notification letters describing a specific timeline have been made public as of this writing.
What Information Was Breached?
National Kidney Registry has not published an itemized list of the specific data involved. Based on the nature of the organization’s work and the categories described in early reporting, the information potentially at risk includes full names, contact information such as addresses and phone numbers, medical and health information related to transplant status, and donor and recipient matching records. A complete, confirmed list of affected data types has not been publicly disclosed.
What You Can Do
If you have an account or relationship with National Kidney Registry, whether as a donor, recipient, applicant, or staff member, there are steps you can take while more information becomes available:
- Monitor your credit reports regularly for unfamiliar accounts or inquiries
- Watch for signs of medical identity theft, such as unexpected medical bills or unfamiliar insurance claims
- Consider placing a fraud alert or credit freeze with the three major credit bureaus
- Be cautious of unsolicited emails, texts, or calls referencing your donor or patient status
- Contact National Kidney Registry directly to ask whether your information was involved
File a Data Breach Lawsuit Against National Kidney Registry
If you believe your personal or health information may have been exposed in the reported National Kidney Registry data breach, you may have legal options available to you.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.