Were you recently affected by a data breach?

National Kidney Registry Data Breach

National Kidney Registry, a nonprofit that coordinates kidney paired-donation transplants nationwide, was reportedly targeted by the Dire Wolf ransomware group in August 2026. The attackers claim to have stolen 253 gigabytes of data, potentially exposing donor, recipient, and staff information.

National Kidney Registry
Date of Breach: Reported August 2026 (Dire Wolf ransomware claim)
CAU logo

Who was affected:

Clients of National Kidney Registry

Impacted Data:

Names, contact information, medical and health information, donor and recipient matching records

National Kidney Registry, a nonprofit organization that coordinates kidney paired-donation transplants across a nationwide network of transplant centers, has reportedly been targeted in a ransomware attack. Reports indicate that donors, transplant recipients, applicants, and staff connected to the registry may have had personal and health information exposed as a result. Organizations that are trusted with sensitive medical and personal data have a responsibility to keep that information secure, and when that trust is broken, those affected deserve to know what happened and what is being done about it.

National Kidney Registry’s Data Breach Investigation

According to an August 25, 2026 post on the dark web security tracking site Ransomware.live, the hacker group Dire Wolf claimed responsibility for the attack and reported exfiltrating approximately 253 gigabytes of data from National Kidney Registry. A separate dark web monitoring service, Breachsense, similarly reported that Dire Wolf claimed to be behind the intrusion. As of this writing, National Kidney Registry has not publicly confirmed the incident, and no information has been made available about the specific scope of the alleged breach or how many individuals may be affected.

Ransomware groups that publish claims on leak sites typically use these postings as leverage to pressure a victim organization into paying a ransom, and a leak-site listing alone is not independent confirmation that a breach occurred or that any particular category of data was actually taken. Even so, incidents like this are taken seriously by regulators and by the individuals whose information may be implicated, because healthcare and nonprofit organizations that manage transplant coordination hold uniquely sensitive records, including details about a person’s medical history and their relationship to an active or pending organ donation.

Healthcare-adjacent organizations, including hospitals, medical registries, and coordination nonprofits, have increasingly become targets for ransomware groups in recent years. These organizations often maintain large volumes of highly sensitive personal and health information while relying on interconnected networks of hospitals, laboratories, and outside vendors, any one of which can present an opportunity for attackers to gain access. Once inside a network, ransomware actors frequently combine data theft with extortion, threatening to publish stolen files unless a ransom is paid, which is consistent with the pattern reported in connection with this incident.

When an organization experiences a suspected breach, state and federal notification laws generally require that affected individuals be notified within a specific window once the scope of the incident is understood, though the exact timeline can vary depending on the type of data involved and the states where affected individuals reside. Investigations of this kind typically involve outside cybersecurity specialists working to determine how the attackers gained access, what systems were affected, and which records may have been viewed or copied, a process that can take weeks or longer to complete even after a breach is first suspected.

The categories of information reportedly at risk in this incident, including full names, contact details, and health and donor-matching records, are the kind of information that can be misused for medical identity theft or targeted phishing schemes. Medical identity theft in particular can be difficult to detect, since fraudulent claims filed using a victim’s stolen health information may not surface until an insurer or provider flags unusual activity, and correcting a compromised medical record can be a lengthy process once it happens.

When Did This Breach Occur?

Dire Wolf’s claim regarding National Kidney Registry surfaced publicly on August 25, 2026, and the group indicated the underlying intrusion occurred around the same date. National Kidney Registry has not published its own account of when the incident began or when it was first discovered internally, and no official notification letters describing a specific timeline have been made public as of this writing.

What Information Was Breached?

National Kidney Registry has not published an itemized list of the specific data involved. Based on the nature of the organization’s work and the categories described in early reporting, the information potentially at risk includes full names, contact information such as addresses and phone numbers, medical and health information related to transplant status, and donor and recipient matching records. A complete, confirmed list of affected data types has not been publicly disclosed.

What You Can Do

If you have an account or relationship with National Kidney Registry, whether as a donor, recipient, applicant, or staff member, there are steps you can take while more information becomes available:

  • Monitor your credit reports regularly for unfamiliar accounts or inquiries
  • Watch for signs of medical identity theft, such as unexpected medical bills or unfamiliar insurance claims
  • Consider placing a fraud alert or credit freeze with the three major credit bureaus
  • Be cautious of unsolicited emails, texts, or calls referencing your donor or patient status
  • Contact National Kidney Registry directly to ask whether your information was involved

File a Data Breach Lawsuit Against National Kidney Registry

If you believe your personal or health information may have been exposed in the reported National Kidney Registry data breach, you may have legal options available to you.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: Reported August 2026 (Dire Wolf ransomware claim)
Date of Breach: Reported to the Vermont Attorney General on August 25, 2026
Date of Breach: Reported to the Vermont Attorney General on August 26, 2026
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.