« All news

New threat group

Spirals, a newly emerged ransomware group with a strong focus on healthcare

A previously unknown actor calling itself Spirals launched its leak site on 14 September 2026 and has posted seven entries, most of them healthcare organisations in North America. Its sudden arrival is a good reason to revisit basic anti-extortion defences.

What happened

On 14 September 2026 a new actor identifying itself as Spirals appeared on the digital extortion scene. According to RansomLook tracking, the group has published seven entries on its leak site since that date, a high rate of activity for a newcomer operating for barely two weeks.

Most entries went up on the launch day itself (14 September), with two later additions on 18 and 26 September. It is worth stressing that these postings are claims made by the group: a listing does not, in itself, confirm the scope of an incident or what information may be affected, unless the organisation issues an official statement or the claim is independently verified.

Who the group is

Spirals does not appear in established threat databases such as MISP Galaxy or MITRE ATT&CK, and it does not match the name of any known group. It is therefore an emerging actor whose initial access vectors and tooling are not yet publicly documented.

The profile of the claimed organisations does say something about its focus: four of the seven are in healthcare (in Canada and the United States, including service and technology providers to the sector), with the remainder spread across professional services, technology and transport and logistics, including one entity based in Oman. The pattern looks opportunistic, with a tilt towards healthcare supply chain providers.

What organisations can do

With no documented technical profile for this group, the sensible response is to strengthen the controls that block most extortion intrusions, whoever the attacker is:

Our recommendation

If your organisation works in healthcare or supplies technology services to the sector, it is prudent to assume a higher level of exposure over the coming weeks and to bring forward a review of remote access and supplier risk. Monitoring public mentions of your brand also helps you react before an incident turns into a reputational crisis.

About the group: Spirals

Claims are published by the criminal groups themselves and are unverified until the organisation or the press confirms them. Names of natural persons (sole traders, individual professionals) are anonymised under the GDPR. We never link to leak sites or stolen data. To request the removal or anonymisation of an entry, contact the site administrator.