National Kidney Registry Data Breach Exposes Patient and Donor Health Information

Published: 25 August 2026
Healthcare data breach illustration
Breach Discovery: Not Publicly DisclosedBreach Notification: August 2026

A ransomware group called direwolf claimed a cyberattack on the National Kidney Registry, a nonprofit that coordinates kidney donations nationwide. The breach may affect donors, transplant patients, and staff, potentially exposing names, contact details, and health information. Notification occurred in August 2026. Affected individuals should monitor credit reports and watch for medical identity theft immediately.

CompanyNational Kidney Registry
IndustryHealthcare
Data Types ExposedFull Names, Contact Information, Medical and Health Information, Donor and Recipient Matching Records, Other Personally Identifiable Information
People AffectedNot Publicly Disclosed
Attack MethodRansomware
Regulators NotifiedNot Publicly Disclosed

What Happened in the National Kidney Registry Data Breach?

The National Kidney Registry has confirmed a cybersecurity incident tied to a ransomware group that calls itself direwolf. The nonprofit coordinates kidney paired donation programs across a network of US transplant centers. As a result, any breach of its systems raises serious concerns for donors and patients alike.

According to available reporting, the direwolf group claimed responsibility for infiltrating the organization’s network and stealing data before the intrusion became public. The exact breach discovery date has not been publicly disclosed. However, the organization issued notification of the incident in August 2026, which is when the broader public first learned of the attack.

Because ransomware groups like direwolf typically combine data theft with extortion, the incident likely involved unauthorized access to internal systems followed by the removal of sensitive files. In response, the National Kidney Registry appears to have launched an internal review to determine what happened and which records were affected. As is common in these cases, a forensic investigation would normally be used to trace how attackers got in and what they took.

At this stage, many technical details remain unclear. For instance, the specific method used to gain initial access has not been confirmed publicly. Still, the involvement of a known ransomware actor suggests this was a deliberate, targeted attack rather than an accidental exposure.

Who was affected?

The population affected by this breach likely includes kidney donors, transplant candidates, and possibly staff connected to the National Kidney Registry’s national network. Because the organization works directly with transplant centers across the country, the exposure could reach individuals in multiple states. This means the breach is not limited to a single region or hospital system.

The exact number of affected individuals has not been publicly disclosed. As a result, it is currently impossible to say with certainty how many donors or patients were impacted. Given the sensitive nature of organ transplant coordination, however, even a modest number of affected records could represent deeply personal medical information.

It also remains unclear whether minors were among those affected, since transplant registries sometimes include younger patients awaiting compatible kidneys. In addition, both current and former participants in the donation program could be included in the exposed data. Anyone who has interacted with the registry, whether as a donor, recipient, or applicant, should consider themselves potentially affected until more specific information becomes available.

What Information Was Potentially Exposed?

Because the National Kidney Registry manages sensitive health coordination data, the types of information at risk in this breach are likely to be highly personal. While a complete, itemized list has not been made public, the nature of the organization’s work points to several probable categories of exposed data.

  • Full names
  • Contact information such as addresses and phone numbers
  • Medical and health information related to transplant status
  • Donor and recipient matching records
  • Other personally identifiable information tied to registry participation

If this information was indeed accessed or stolen, affected individuals could face a heightened risk of identity theft. Medical identity theft is a particular concern, since stolen health records can be used to file fraudulent insurance claims or obtain medical services under someone else’s name. This type of fraud can be difficult to detect and even harder to unwind.

In addition, exposed contact details could be used in targeted phishing schemes. Scammers often pose as a healthcare provider or registry official to trick victims into revealing more information. Because the stolen data may include real details about someone’s transplant journey, these scam attempts could appear unusually convincing and hard to spot.

What is the company doing?

In response to the incident, the National Kidney Registry appears to have taken steps to investigate the scope of the attack. Organizations facing ransomware incidents typically work with outside cybersecurity specialists to contain the breach and assess what data was taken. This process often takes weeks or months to fully complete.

Following the confirmation of the breach, the organization moved to notify affected parties in August 2026. Going forward, the registry will likely continue monitoring its systems for further suspicious activity. Many organizations in similar situations also strengthen network defenses and review vendor access controls after an attack like this.

What Should Affected Individuals Do?

Monitor Your Credit Reports

Because personal information may have been exposed, affected individuals should regularly check their credit reports for unfamiliar accounts or inquiries. You can request a free copy of your credit report from each of the three major bureaus once a year through AnnualCreditReport.com. Reviewing these reports closely can help you catch fraud early.

In addition, consider spacing out your requests so you can check your credit report every few months throughout the year. This gives you more frequent visibility without any added cost. If you notice anything unusual, report it to the credit bureau immediately and consider speaking with a data breach attorney about your options.

Watch for Medical Identity Theft

Since health-related information may have been part of this breach, affected individuals should watch closely for signs of medical identity theft. This can include unexpected medical bills, unfamiliar insurance claims, or letters about services you never received. Because medical fraud can affect your health records, it is important to catch it early.

To protect yourself, request an itemized statement from your health insurer if anything seems off. You should also ask your insurance provider whether they offer a way to flag your account for suspicious activity. Correcting fraudulent medical records can be a lengthy process, so early action matters.

Set Up Fraud Alerts or a Credit Freeze

If your Social Security number or other sensitive identifiers were part of this breach, placing a fraud alert or credit freeze can add an extra layer of protection. A fraud alert requires lenders to verify your identity before opening new credit in your name. This step is free and generally lasts one year.

A credit freeze goes a step further by blocking most new credit applications entirely until you lift it. Because this can prevent identity thieves from opening accounts, it is one of the strongest protective measures available. You can request a freeze directly through each of the three credit bureaus.

Stay Alert to Phishing Attempts

Following a healthcare data breach, scammers often send emails or texts pretending to be from a trusted organization. Therefore, affected individuals should be cautious of unexpected messages asking for personal details or login credentials. Always verify the sender before clicking any links or downloading attachments.

If you receive a suspicious message referencing your donor or patient status, do not respond directly. Instead, contact the organization through its official phone number or website to confirm whether the message is legitimate. This simple habit can prevent a phishing attempt from turning into a bigger problem.



Related Data Breaches

View the full list of tracked data breaches →