Qilin ransomware claims New World Diagnostics
Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.
Ransomware group Qilin has listed New World Diagnostics as a victim on its leak site, exposing compromised credentials and attack surface data.
Ransomware.live has tracked a listing by the Qilin ransomware group naming New World Diagnostics as a victim. The entry, sourced from the group's leak site, indicates 139 compromised user accounts and 13 third-party employee credentials exposed, alongside 13 identified external attack surface points and associated DNS records for the victim's domain. No details on the initial access vector, data exfiltrated, or ransom demands are provided in this listing.
The posting includes a sponsored note referencing Hudson Rock's infostealer intelligence tooling, suggesting a possible link between credential-stealing malware infections and the eventual ransomware compromise, though no specific infostealer family or campaign is named in connection with this victim. Defenders in the diagnostics/healthcare sector should treat this as a reminder that leaked or stolen credentials (via infostealers or third-party compromise) remain a common precursor to ransomware intrusions.
As this is a brief victim-listing entry rather than a full incident report, there is limited technical detail for detection or mitigation. Organizations should monitor for credential exposure via infostealer logs, enforce MFA and credential hygiene for third-party/vendor accounts, and review external attack surface exposure, particularly for smaller healthcare/diagnostics providers that may lack mature security operations.
Mentioned in this report
Source reporting: https://www.ransomware.live/id/TmV3IFdvcmxkIERpYWdub3N0aWNzQHFpbGlu
What this brief leaves out
This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.
It sits in a corpus of 11,175 reports from 151 sources, 2,686 of them written in the last seven days, and it grows through the day.
A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.
Create a free account What it costs