>
av.Amit VijayanCYBERSECURITY & RESEARCHLet\u2019s connect
Back to the library

Cyber news

Daily Cyber Threat Brief — October 10, 2026: Chaos Ransomware Claims 1.5 TB of Astrana Health Patient Data

Thumbnail for: Daily Cyber Threat Brief — October 10, 2026: Chaos Ransomware Claims 1.5 TB of Astrana Health Patient Data

🗂️ CASE FILE — October 10, 2026

Lead story: On October 9, 2026, the ransomware group Chaos claimed it exfiltrated 1,500 GB of data from Astrana Health, a US healthcare technology company, and published it after the company's management declined to pay. The group says the haul includes patient diagnoses and personal information covering millions of patients. This is an attacker claim, not a confirmed breach — Astrana has not confirmed the Chaos intrusion. The claim lands less than three weeks after Astrana filed an SEC Form 8-K disclosing a material cybersecurity incident: attackers spoofed the company's own corporate telephone number, ran a vishing campaign against employees, and accessed company servers. The company says it is still assessing what was taken, and it previously said no ransomware was confirmed in that September intrusion. Threat intelligence monitors also link infostealer activity (49 compromised users, 260 passwords, 59 exposed cookies) to Astrana's environment, suggesting stolen credentials may have preceded the ransomware play.

Why it leads: Healthcare data theft at claimed terabyte scale, layered on an already SEC-confirmed incident, makes this the day's most consequential story — even with the attribution caveats. If the Chaos claim verifies, it would be one of the largest healthcare data thefts of the year.

Today's top stories

  • Chaos ransomware claims 1.5 TB of Astrana Health patient data — group says millions of patients' diagnoses published after failed payment talks; company has not confirmed the claim. (United States, healthcare)
  • Ransomware knocks Japan's IDCF Cloud offline — 495 companies and local governments affected — IDC Frontier confirms third-party ransomware hit East Japan Region 1 on Oct 7; consoles disabled across all regions. (Japan, cloud)
  • ASOS names the attack vector: social engineering, not a Snowflake breach — UK retailer says attackers impersonated a trusted contact to steal employee credentials and pull data from third-party platforms. (United Kingdom, retail)
  • CISA adds five Flax Typhoon-exploited flaws to the KEV catalog — federal agencies given an October 11 deadline; a decade-old ProFTPD RCE (CVSS 10.0) is on the list. (Advisory)

Chaos ransomware claims 1,500 GB of Astrana Health patient data after failed deal

Astrana Health, the healthcare technology company behind roughly 20,000 affiliated medical providers, is now the named victim in a ransomware leak-site posting by the group Chaos. Monitors of the group's dark-web leak site recorded the listing on October 9, 2026: the attackers claim they stole 1,500 GB — diagnoses and personal information of millions of patients — and published it in full after management withdrew from ransom negotiations to save money. The posting is corroborated by multiple leak-site trackers, but nothing in the post independently proves data was exfiltrated, and Astrana has not publicly confirmed any Chaos intrusion.

That claim sits on top of an already-confirmed incident. On September 23, 2026, Astrana filed an SEC Form 8-K reporting a material cybersecurity incident: threat actors spoofed Astrana's main corporate telephone number and ran a series of social-engineering attempts, impersonating company personnel to get unauthorized access to company systems. The company believes certain private and confidential information on its servers was accessed or acquired without authorization. It engaged a third-party forensics firm, notified law enforcement and regulators, reset credentials, restricted remote-access tools, and restored systems from clean backups. At that time it explicitly said the extent of data taken was still under assessment.

Investigation notes
  • Attribution gap: The SEC filing identifies no threat actor and no ransomware. The Chaos leak-site claim (Oct 9) names a group but supplies no sample files or forensic proof. Treat the two as connected but separately verified facts: the intrusion is confirmed by the company; the 1,500 GB figure is an attacker's claim.
  • Infostealer precursor: Threat-intel analysis tied to the claim reports 49 compromised users, 260 passwords, 59 cookies, and seven exposed credential URLs from infostealer activity against Astrana's environment. Stolen credentials harvested by infostealers are a common first foothold before ransomware deployment.
  • Patient-data exposure: The claimed data includes patient diagnoses — the most sensitive healthcare data category, with long-lived fraud, extortion, and HIPAA exposure. Health data cannot be reissued like a card number.
  • Defender read: Healthcare security teams should audit credential hygiene (infostealer fallout), tighten vishing defenses at the help desk, and treat any negotiated-then-abandoned ransom as a publication trigger, not a resolution.

Ransomware attack on Japan's IDCF Cloud knocks 495 companies and governments offline

IDC Frontier, the SoftBank Group subsidiary that operates IDCF Cloud, confirmed a third-party ransomware attack against its East Japan Region 1 data-center cluster beginning around 3:40 AM JST on October 7, 2026. The provider isolated the region and shut down network and systems to stop the spread, taking 495 companies and local governments offline. Named public-sector customers include Ibaraki Prefecture and the Ibaraki prefectural police; a Nissui logistics subsidiary reported nationwide hub disruption. IDC Frontier proactively disabled customer access to management consoles in all regions while it verifies their security, and told customers to rebuild in a separate environment from their own backups.

An attacker message seen by locked-out customers claims the breach took seven minutes, and alleges encryption of 225 databases (3.6 PB of data), reach across 239 hypervisors, sealing of 16,000 VM disks, and wiping of 554,153 snapshots — attacker claims, unverified. IDC Frontier has not disclosed the intrusion route, the ransomware family, whether customer data was taken, or a restoration date. As of October 9 the company was still contacting affected customers individually.

Investigation notes
  • Blast-radius lesson: A single cloud region — not even a single customer — took down unrelated government and private-sector services. Shared infrastructure multiplies ransomware impact across tenants that have nothing else in common.
  • Snapshot destruction is the kill shot: If the claim of 554,153 wiped snapshots holds, customers' in-cloud recovery points are gone, which is why the provider is telling customers to restore from off-cloud backups they hold themselves.
  • Console shutdown across all regions signals the provider could not immediately rule out control-plane compromise beyond East Japan Region 1 — a wider review is still underway.
  • Defender read: Cloud customers should verify that backup isolation is contractual, not assumed — backups stored inside the same provider region are not independent of the provider's own incident.

ASOS names the attack vector: social engineering against an employee, not a Snowflake compromise

ASOS, the UK fashion retailer, told affected customers on October 8, 2026 that the data breach it disclosed on October 6 began with a social-engineering attack against an employee. An unauthorized party impersonated a trusted contact to obtain login credentials, then used those credentials to pull data from certain third-party platforms used by ASOS. That answers the open question from the initial disclosure and directly contradicts the attackers' own story.

The group calling itself the Xuanye Group had claimed it fully compromised ASOS's Snowflake instance — a claim delivered via an unauthorized in-app push notification ("ASOS HACKED") on October 6. ASOS confirmed only that a third-party notification platform had been accessed and that names and contact details may have been exposed. Snowflake separately denied any compromise of its platform. The October 8 update is ASOS's first confirmed attribution: credential theft through impersonation, routed through third-party platforms rather than the data warehouse.

Investigation notes
  • Threat-actor theater vs. facts: Attackers routinely claim bigger access than they have — "we fully compromised Snowflake" was a pressure tactic, not a fact. Independent verification from the platform operator (Snowflake's denial) and the victim's forensics mattered more than the loud claim.
  • Impersonation + third-party access: The vector — a trusted-contact impersonation yielding employee credentials, then abuse of third-party platforms — is the same playbook seen in the Astrana vishing incident above. Help-desk and vendor-portal workflows remain the softest path in.
  • Notification infrastructure as attack surface: The initial compromise was of a third-party push-notification platform, which the attackers used to message customers directly. Vendors with write access to your customer-facing channels need the same scrutiny as data vendors.

CISA adds five Flax Typhoon-exploited flaws to the KEV catalog; federal deadline is October 11

On October 9, 2026, the US Cybersecurity and Infrastructure Security Agency (CISA) added five vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog after they were abused by the China-linked threat actor Flax Typhoon. Flaws on the list include CVE-2015-3306 (ProFTPD improper access control, CVSS 10.0), CVE-2021-3199 (ONLYOFFICE Docs path traversal leading to RCE, CVSS 9.8), CVE-2023-22894 (Strapi cleartext storage of sensitive information, CVSS 7.2), and CVE-2016-3081 (Apache Struts command injection, CVSS 8.1). Federal civilian agencies must remediate by October 11.

Investigation notes
  • Ancient flaws, active campaigns: A 2015 ProFTPD bug with a perfect 10.0 and a 2016 Struts injection landing in a 2026 nation-state campaign is the standard reminder — known-exploited does not mean recently disclosed. Flax Typhoon mines old, unpatched edge and web-application software.
  • Deadlines are signals: A two-day federal remediation window signals high confidence the flaws are under active, broad exploitation — private-sector teams should treat the same deadline as their own.

In brief: leak-site claims and arrests to watch

Japan arrests in the Qilin case: Japan's National Police Agency and Germany's North Rhine-Westphalia investigators confirmed that a 28-year-old Russian believed to be a leading member of the Qilin ransomware group was detained in Japan in May and handed to Germany on October 2, despite the absence of an extradition treaty — German investigators say they had infiltrated the group.

Osaka Metropolitan University: the university confirmed ransomware took down about 500 servers and most backups; classes resumed October 9 on temporary systems.

Leak-site monitoring (all claims unverified, attacker assertions only): Nightspire listed Heidi's Events & Catering (US); SafePay listed a Swiss hotel and German construction firm dwi-bau.de; DeadLock listed idi pharma and US machine-vision distributor Saber1; the UmBra group listed IIT Roorkee (India) and SOCOCO; BlackX listed Bayer and enTouch alongside the Astrana claim. None of these listings include independently verified evidence of compromise.

Incident timeline — September 22 to October 10, 2026

DateEvent
Sep 22, 2026Astrana Health determines a social-engineering (vishing) intrusion is a material cybersecurity incident.
Sep 23, 2026Astrana files SEC Form 8-K disclosing spoofed-caller-ID vishing and unauthorized server access.
Oct 2, 2026Suspected Qilin ransomware member handed from Japan to German authorities.
Oct 6, 2026ASOS discloses breach after "ASOS HACKED" push notifications; Xuanye Group claims Snowflake compromise; Snowflake denies.
Oct 7, 2026Ransomware hits IDCF Cloud East Japan Region 1 (~3:40 AM JST); 495 companies and local governments go offline; consoles disabled.
Oct 8, 2026ASOS confirms root cause: social engineering against an employee, credential theft via third-party platforms.
Oct 9, 2026Chaos ransomware claims 1,500 GB of Astrana Health patient data after failed deal (unverified claim); CISA adds five Flax Typhoon-exploited flaws to KEV with Oct 11 deadline; multiple leak-site listings (SafePay, DeadLock, UmBra, Nightspire, BlackX).
Oct 9, 2026Osaka Metropolitan University resumes classes on temporary systems after ransomware took down ~500 servers.
Oct 10, 2026This brief published.

Source links

Keep exploring.

All articles