SYS::ONLINE
Wasteland.
Briefs1855
Issues23
SinceFeb 2026
LIVE
█ Ransomware STATISTA-QUIRONSAL 2026-08-11

Statista and Quirónsalud: DireWolf Ransomware Leak Site Listings

"The DireWolf ransomware operation has posted two major European organisations to its extortion infrastructure within the same 24-hour window: German market-data provider Statista GmbH and Spanish private hospital group…"

The DireWolf ransomware operation has posted two major European organisations to its extortion infrastructure within the same 24-hour window: German market-data provider Statista GmbH and Spanish private hospital group Quirónsalud. What is confirmed at this point is the listing itself, not the breach. Neither victim has issued a public statement, no regulator filing or national CERT advisory has surfaced, and none of the available reporting is PRIMARY-tier. The threat-intelligence aggregator HookPhish logs the Statista entry with a breach timestamp of 2026-08-10T18:29:15 UTC and a discovery timestamp of 2026-08-10T18:57:53 UTC. UNDERCODE NEWS, reporting on 11 August, describes the Quirónsalud claim as discovered on 10 August and states plainly that no independent evidence of intrusion, exfiltration, encryption or service disruption accompanied it. Treat both entries as unverified actor claims until a victim, regulator or forensic vendor says otherwise.

What Happened

DireWolf added Statista GmbH to its victim listings on 10 August 2026. HookPhish records the target domain as statista.com, the region as DE, and the sector as Professional Services, with the leak-site descriptor rendered as "Data Collection & Internet Portals." UNDERCODE NEWS characterises that same descriptor as an allegation of unauthorised access to Statista systems with claimed disruption to the company's data-collection activity and portal operations. That reading is an interpretation of the actor's own category label, not corroborated damage assessment, and the two accounts should not be conflated.

The Quirónsalud claim is thinner still. UNDERCODE NEWS attributes it to a post by Cybersecurity News Everyday stating that DireWolf claimed a successful attack against the Spanish healthcare group, discovered 10 August 2026. There is no ransom demand, no stated data volume, no screenshots, no sample files, and no technical indicators in the public record. The listing does not establish whether patient-facing services, laboratories, administrative infrastructure, medical devices or third-party providers were touched at all.

A third DireWolf listing landed in the same batch and has been largely overlooked: AliveCor, Inc., a US medical-device and AI company at alivecor.com, logged by HookPhish with a breach timestamp of 2026-08-10T18:26:14 UTC and discovery at 18:58:25 UTC. Three victims across two continents and three unrelated sectors, all stamped within roughly half an hour of each other, is the more analytically interesting fact than any single listing. It suggests a batch publication event rather than three separate intrusions concluding simultaneously, which in turn means the actual compromise dates may sit weeks or months earlier.

What Was Taken

Nothing has been substantiated. Across all seven available sources there is not a single record count, data category, file-tree sample or proof-pack reference attached to either the Statista or the Quirónsalud claim. This is the honest state of the evidence and it is worth stating flatly, because leak-site listings without proof material are a recognised pattern: DireWolf is documented as running a double-extortion model combining data theft, encryption and publication threats, and groups operating that model routinely stage a listing during a negotiation window before any data is released.

The exposure envelope, if the claims hold, differs sharply between the two. Statista aggregates commercial, market and statistical data alongside a large subscriber base of corporate and academic customers, so the realistic worst case is customer account data, contract and billing records, and licensed dataset content. Quirónsalud is a hospital operator, which places clinical records, identity documents and insurance data in scope, plus the operational continuity of care delivery. Spanish reporting cited by headtopics notes that clinical histories trade for around USD 1,000 each, which is the economic reason healthcare listings tend to carry credible follow-through even when the initial post is bare.

Why It Matters

The sector context makes the Quirónsalud listing the more consequential of the two regardless of how it resolves. Per figures attributed to INCIBE and circulated in Spanish trade press, cyberattacks and data theft in Spain rose 26% in 2025, healthcare ranks as the fourth most-affected sector nationally and the most-affected sector across Europe over the last four years of available data, hospitals account for 42% of all healthcare-sector incidents, and 54% of attacks on European healthcare are ransomware. These are OTHER-tier aggregate statistics rather than incident evidence, but they establish that a hospital-group listing sits squarely inside an active and well-documented targeting trend, not at its margins. Spanish private-sector healthcare bodies are already pushing for reinforced data protection and NIS2 alignment on exactly this basis.

For Statista, the risk is downstream rather than clinical. A data platform embedded in the research and reporting workflows of thousands of enterprises is a concentration point: compromise there is a supply-chain event for its customers, not just an incident for the vendor. That framing echoes the parallel campaigns running through the same period. Medtronic is currently notifying customers of a ShinyHunters-attributed breach that originated at a third-party platform rather than its own systems, and Rescana's write-up of Microsoft research documents ShinyHunters and affiliated clusters including UNC6040, UNC6240, UNC6395 and Storm-3138/Icarus abusing OAuth grants, vendor integrations and misconfigured guest access to reach Salesforce and SaaS environments at Google, Chanel, Pandora and others. Those incidents are unrelated to DireWolf and should not be attributed to it, but they define the environment defenders are operating in: the platform holding your data is now as much of an attack surface as your own network.

The Attack Technique

No initial-access vector has been published for either the Statista or the Quirónsalud claim. Nobody has identified an exploited CVE, a compromised credential set, a phishing lure or an accessed remote-access appliance, and there are no IOCs, ransom note artefacts or encryptor samples in the public record for these listings.

What is documented about DireWolf generally is the double-extortion pattern already described, along with observed targeting across multiple countries and sectors, which the AliveCor listing reinforces. Anyone circulating a specific intrusion chain for these two victims today is filling in a blank the sources do not fill. The broader ransomware baseline, as HookPhish notes in its own guidance, remains stolen credentials and phishing as the dominant entry points, and that is a prior worth acting on rather than a finding specific to this incident.

What Organizations Should Do

  1. Statista and Quirónsalud customers: treat this as a watch item, not a confirmed exposure. Do not initiate customer notification or public statements on the basis of a leak-site entry. Do open a tracked case, assign an owner and set a review cadence so you are not caught flat if proof data appears.
  2. Inventory your data held by both organisations. Know what you have uploaded, licensed, integrated or shared, and identify which API keys, SSO integrations and service accounts connect your environment to theirs. Rotate any credentials shared with or stored at either provider as a low-cost precaution.
  3. Hunt for credential-based access now. Given that stolen passwords and phishing dominate ransomware entry, prioritise reviewing authentication logs for impossible-travel and anomalous-geography logins, legacy protocol use bypassing MFA, and new or modified service principals. Enforce phishing-resistant MFA on all remote access and privileged accounts.
  4. Audit third-party and OAuth integrations, especially in SaaS. The Medtronic and Salesforce cases show intrusions arriving through vendor connections rather than perimeter exploits. Enumerate every connected app and OAuth grant in your CRM and productivity suites, revoke unused ones, restrict guest and external sharing permissions, and require approval for new integrations.
  5. Healthcare operators: rehearse the downtime path. Validate offline-capable clinical workflows, confirm that backups of clinical systems are immutable and restore-tested rather than merely running, and segment medical devices and laboratory systems from general IT so an encryption event cannot cascade into care delivery.
  6. Monitor for proof-pack publication and log what changes. Track the DireWolf listings for the appearance of samples, file trees or record counts, and record the timeline. If proof material lands, that is the trigger to move from watch item to incident response, and the timestamp gap between listing and proof is itself useful intelligence about where each negotiation stands.

Sources: DireWolf Ransomware Claims Two New Targets in Germany and Spain — S... | Direwolf Ransomware Claims a Hit on Spain’s Quirónsalud: A New Warn... | Los ciberataques y las amenazas digitales centran sus ofensivas en... | Medtronic notifies customers impacted by ShinyHunters data breach —... | Active Exploitation Alert: ShinyHunters Abuse OAuth and Vendor Inte... | Ransomware Group direwolf Hits: Statista GmbH | Ransomware Group direwolf Hits: AliveCor, Inc.