Threat reportData BreachTL-2026-1916

Cardiology Associates of Port Huron (Port Huron Heart Center) Breached by Orova Ransomware Group — 144.00 GB of Patient Data Exfiltrated

highACTIVE

Cardiology Associates of Port Huron (Port Huron Heart (TL-2026-1916) is a high-severity data breach, first published 2026-08-06. It is attributed to Orova with medium confidence, affects Cardiology Associates of Port Huron, P.C. Healthcare Services, maps to 16 MITRE ATT&CK techniques (T1003, T1005, T1018), and is covered by 9 detection rules and 7 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
16MITRE ATT&CK
Actors
1Orova
Detection rules
9SPL · KQL · Sigma
IOCs
7Indicators of compromise

Key facts for TL-2026-1916

Threat ID
TL-2026-1916
Severity
HIGH
Status
ACTIVE
Category
DATA_BREACH
First published
Last reviewed
Attribution
Orova
Attribution confidence
MEDIUM
Motivation
FINANCIAL
Target sectors
health, manufacturing, information-technology, insurance, construction, retail, finance, hospitality, transport, professional-services
Target regions
united states of america, hong kong, taiwan, brazil, egypt, japan
Detection rules
9
Indicators of compromise
7

Malware and tooling in Cardiology Associates of Port Huron (Port Huron Heart

Malware and tooling: Orova ransomware, OROVA ransomware operation

How Cardiology Associates of Port Huron (Port Huron Heart works

Cardiology Associates of Port Huron, P.C. (porthuronheartcenter.com), a Michigan-based cardiovascular practice operating since 1974, was breached by the Orova ransomware group. Over 144.00 GB of patient data (244,215 files) was exfiltrated during a June 2026 intrusion, with Orova posting an extortion notice on their Tor-hosted leak site on July 10, 2026, threatening public release of the stolen data unless a company representative initiated negotiations. As of August 6, 2026, the practice has not publicly disclosed or confirmed the incident, placing them at risk of HIPAA breach notification penalties.

On July 10, 2026, the Orova ransomware group added Cardiology Associates of Port Huron, P.C. (d/b/a Port Huron Heart Center) to their Tor-hosted data leak site, claiming responsibility for an intrusion that resulted in the theft of 144.00 GB of data (244,215 files). The group posted the extortion notice with the statement: "The full leak will be published soon, unless a company representative contacts us via the channels provided," indicating that negotiations had not yet begun as of the posting date.

Cardiology Associates of Port Huron is a physician-owned partnership founded in 1974, headquartered at 1222 10th Avenue, Port Huron, Michigan. The practice employs 3 interventional cardiologists, a vascular interventionist, an electrophysiologist, and 3 non-invasive cardiologists supported by nurse practitioners, physician assistants, registered nurses, and exercise physiologists. It operates 7 satellite clinics spanning north into Michigan's Thumb region and south to Algonac.

Orova is an emerging ransomware group first observed in May 2026, classified by WatchGuard Technologies as a "Data Broker" operation employing double-extortion tactics (data theft plus encryption), with an additional tactic of "free data leaks" — publicly releasing stolen data without payment as a coercive measure. The group has claimed 24+ victims across 6 countries (United States — 13 victims, Hong Kong — 5, Taiwan — 4, with single victims in Brazil, Egypt, and Japan), targeting diverse sectors including healthcare (4 confirmed victims — the most-hit sector), manufacturing, finance, IT, insurance, and construction.

Orova's observed attack chain includes: purchasing compromised credentials from infostealer markets (~24% of victims had domain credentials detectable in infostealer markets prior to attack per Hudson Rock/ransomware.live data), exploiting unpatched vulnerabilities in public-facing applications, deploying spear-phishing campaigns, conducting internal reconnaissance and Active Directory profiling, exfiltrating sensitive data before encryption, identifying and destroying/corrupting backups to eliminate recovery options, and deploying mass encryption across file servers, domain controllers, email servers, and operational systems.

The group operates a sophisticated extortion infrastructure including a Tor-hosted leak site (mll5ddmdzgiq2siv3qnocmmqyiigfpajtc663xtf32qtp6weycyx2hyd.onion), a separate Tor-hosted negotiation/chat portal (ns7y6bxawualjj5rpo5num6syejd7hgaowrndk3r4duxu2iyinzv6hid.onion), and a Tox encrypted messaging ID for direct victim communication. Data exfiltration volumes documented across victims range from 15.90 GB to 64.70 GB.

This breach exposes protected health information (PHI) from a cardiovascular practice, potentially including patient names, medical records, clinical histories, diagnoses, treatment plans, insurance information, Social Security numbers, billing data, and other personally identifiable information (PII). As a HIPAA-covered entity, Cardiology Associates is subject to mandatory breach notification requirements under HIPAA/HITECH, including notification to affected individuals, the HHS Office for Civil Rights (OCR), and potentially local media. The HHS OCR has intensified ransomware enforcement in 2026, issuing four settlements totaling $1,165,000 in April 2026 alone, and has now completed 20 ransomware-related enforcement actions.

No specific technical IOCs (malware hashes, C2 server IPs, encrypted file extensions, ransom note filenames) have been publicly released for Orova as of this report, as the group is too new for detailed reverse-engineering reports from major cybersecurity vendors. Monitoring of Orova's Tor infrastructure, continued victim tracking, and credential exposure assessments remain the primary detection vectors.

MITRE ATT&CK techniques used in TL-2026-1916

Credential Access

T1003 OS Credential Dumping

Collection

T1005 Data from Local System

Discovery

T1018 Remote System Discovery; T1046 Network Service Discovery; T1069 Permission Groups Discovery; T1087 Account Discovery

Lateral Movement

T1021 Remote Services

Initial Access

T1078 Valid Accounts; T1190 Exploit Public-Facing Application; T1566 Phishing

Command and Control

T1095 Non-Application Layer Protocol

Execution

T1204 User Execution

Impact

T1485 Data Destruction; T1490 Inhibit System Recovery

Exfiltration

T1567 Exfiltration Over Web Service

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in Cardiology Associates of Port Huron (Port Huron Heart

  • Cardiology Associates of Port Huron, P.C. — Healthcare Services (Cardiovascular Medicine)
    Vulnerable versions: All systems and patient data prior to June 2026

Remediation for Cardiology Associates of Port Huron (Port Huron Heart

Patches

  • Patch all public-facing applications against known CVEs (VPN, RDP, Exchange, web servers)
  • Apply critical security updates within 24-hour SLA for internet-facing systems
  • Disable unused remote access services (RDP if not required, legacy VPN protocols)

Immediate actions

  • Notify affected patients under HIPAA breach notification requirements within 60 days
  • Engage incident response and forensic investigation team
  • Reset all credentials and enforce MFA across all systems
  • Report to law enforcement (FBI IC3, CISA, HHS OCR)
  • Isolate compromised systems and preserve evidence for forensic analysis
  • Monitor Orova Tor leak site and Tox channels for data publication

Workarounds

  • Restrict outbound Tor network access from corporate environments
  • Block known Orova Tor leak site domains on network proxies and DNS filters
  • Implement application allowlisting to prevent unauthorized executables
  • Enable Windows Event Logging (4688 process creation, 4104 PowerShell) for forensic visibility

Longer-term hardening

  • Implement EDR/XDR with behavioral ransomware detection across all endpoints
  • Deploy network segmentation to limit lateral movement and blast radius
  • Implement immutable/air-gapped backup strategy with offline and offsite copies
  • Establish continuous credential monitoring for infostealer market exposure
  • Conduct regular ransomware tabletop exercises and incident response drills
  • Deploy 24/7 SOC monitoring with threat hunting for ransomware precursors
  • Implement comprehensive vendor risk management for third-party access

Timeline of Cardiology Associates of Port Huron (Port Huron Heart

  • Orova ransomware group first observed in the wild by threat intelligence platforms; begins posting victims to Tor leak site
  • Orova gains initial access to Cardiology Associates of Port Huron network (estimated, based on DataBreaches.net reporting of patient data stolen in June); initial access likely via purchased infostealer credentials, unpatched vulnerability, or phishing
  • Internal reconnaissance and Active Directory profiling performed to map network topology, identify domain administrators, and locate sensitive patient data repositories
  • Approximately 144.00 GB of patient data exfiltrated from Cardiology Associates systems to Orova-controlled infrastructure before encryption deployment
  • Backup systems identified, targeted, and corrupted/destroyed to prevent recovery without paying ransom; mass encryption deployed across file servers, domain controllers, and email servers
  • Orova posts extortion notice on Tor-hosted leak site threatening public release of 144.00 GB of stolen patient data unless company representative initiates negotiations
  • FalconFeeds.io and ransomware.live publicly identify Orova after group posts 24 victims on Tor leak site in single bulk announcement; Orova's total claimed victims reaches 24+ across US, Hong Kong, Taiwan, Brazil, Egypt, and Japan
  • BreachSense and DeXpose index the incident; WatchGuard ransomware tracker confirms Orova has claimed 24+ victims across 6 countries; FalconFeeds.io publishes bulk alert
  • DataBreaches.net publishes detailed report; Cardiology Associates of Port Huron has not publicly disclosed or confirmed the incident; 60-day HIPAA notification clock begins for breach affecting 500+ individuals

Sources cited for Cardiology Associates of Port Huron (Port Huron Heart

Detection coverage for TL-2026-1916

As of 2026-08-06, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1916 across Splunk SPL, Microsoft KQL and Sigma, covering 7 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
7 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats