Spirals, a newly emerged ransomware group with a strong focus on healthcare
A previously unknown actor calling itself Spirals launched its leak site on 14 September 2026 and has posted seven entries, most of them healthcare organisations in North America. Its sudden arrival is a good reason to revisit basic anti-extortion defences.
What happened
On 14 September 2026 a new actor identifying itself as Spirals appeared on the digital extortion scene. According to RansomLook tracking, the group has published seven entries on its leak site since that date, a high rate of activity for a newcomer operating for barely two weeks.
Most entries went up on the launch day itself (14 September), with two later additions on 18 and 26 September. It is worth stressing that these postings are claims made by the group: a listing does not, in itself, confirm the scope of an incident or what information may be affected, unless the organisation issues an official statement or the claim is independently verified.
Who the group is
Spirals does not appear in established threat databases such as MISP Galaxy or MITRE ATT&CK, and it does not match the name of any known group. It is therefore an emerging actor whose initial access vectors and tooling are not yet publicly documented.
The profile of the claimed organisations does say something about its focus: four of the seven are in healthcare (in Canada and the United States, including service and technology providers to the sector), with the remainder spread across professional services, technology and transport and logistics, including one entity based in Oman. The pattern looks opportunistic, with a tilt towards healthcare supply chain providers.
What organisations can do
With no documented technical profile for this group, the sensible response is to strengthen the controls that block most extortion intrusions, whoever the attacker is:
- Enable phishing-resistant multi-factor authentication on VPNs, remote access, email and administrative portals.
- Prioritise patching of internet-facing devices (firewalls, VPN concentrators, file transfer servers) and retire anything out of support.
- Review service accounts and third-party or supplier access, applying least privilege and revoking what is no longer needed.
- Keep isolated, immutable backups and test full restoration, not just the backup job.
- Deploy EDR/XDR with monitoring for anomalous logins and data exfiltration to external storage services.
- Update the incident response plan to include notification to the data protection authority and to affected individuals where applicable.
Our recommendation
If your organisation works in healthcare or supplies technology services to the sector, it is prudent to assume a higher level of exposure over the coming weeks and to bring forward a review of remote access and supplier risk. Monitoring public mentions of your brand also helps you react before an incident turns into a reputational crisis.
About the group: Spirals
Claims are published by the criminal groups themselves and are unverified until the organisation or the press confirms them. Names of natural persons (sole traders, individual professionals) are anonymised under the GDPR. We never link to leak sites or stolen data. To request the removal or anonymisation of an entry, contact the site administrator.