# Qilin ransomware claims New World Diagnostics

Published: 2026-09-28 · Severity: high · Sectors: healthcare
Canonical: https://vorant.io/reports/fe5a5051-a981-5875-b1d1-0d3504a2cf11/qilin-ransomware-claims-new-world-diagnostics

> Ransomware group Qilin has listed New World Diagnostics as a victim on its leak site, exposing compromised credentials and attack surface data.

Ransomware.live has tracked a listing by the Qilin ransomware group naming New World Diagnostics as a victim. The entry, sourced from the group's leak site, indicates 139 compromised user accounts and 13 third-party employee credentials exposed, alongside 13 identified external attack surface points and associated DNS records for the victim's domain. No details on the initial access vector, data exfiltrated, or ransom demands are provided in this listing.

The posting includes a sponsored note referencing Hudson Rock's infostealer intelligence tooling, suggesting a possible link between credential-stealing malware infections and the eventual ransomware compromise, though no specific infostealer family or campaign is named in connection with this victim. Defenders in the diagnostics/healthcare sector should treat this as a reminder that leaked or stolen credentials (via infostealers or third-party compromise) remain a common precursor to ransomware intrusions.

As this is a brief victim-listing entry rather than a full incident report, there is limited technical detail for detection or mitigation. Organizations should monitor for credential exposure via infostealer logs, enforce MFA and credential hygiene for third-party/vendor accounts, and review external attack surface exposure, particularly for smaller healthcare/diagnostics providers that may lack mature security operations.

## Mentioned in this report

- Threat actors: qilin
- Malware: Qilin

1 more detection for this report is in the app: the rules that match its indicators, every rule converted to Splunk SPL and Elastic, Microsoft Defender XDR KQL wherever Defender records the activity, and the YARA and Suricata. A new account gets three days of them free.

Source reporting: https://www.ransomware.live/id/TmV3IFdvcmxkIERpYWdub3N0aWNzQHFpbGlu

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/fe5a5051-a981-5875-b1d1-0d3504a2cf11/qilin-ransomware-claims-new-world-diagnostics.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
