Threat reportData BreachTL-2026-1916
Cardiology Associates of Port Huron (Port Huron Heart Center) Breached by Orova Ransomware Group — 144.00 GB of Patient Data Exfiltrated
Cardiology Associates of Port Huron (Port Huron Heart (TL-2026-1916) is a high-severity data breach, first published 2026-08-06. It is attributed to Orova with medium confidence, affects Cardiology Associates of Port Huron, P.C. Healthcare Services, maps to 16 MITRE ATT&CK techniques (T1003, T1005, T1018), and is covered by 9 detection rules and 7 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 16MITRE ATT&CK
- Actors
- 1Orova
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 7Indicators of compromise
Key facts for TL-2026-1916
- Threat ID
- TL-2026-1916
- Severity
- HIGH
- Status
- ACTIVE
- Category
- DATA_BREACH
- First published
- Last reviewed
- Attribution
- Orova
- Attribution confidence
- MEDIUM
- Motivation
- FINANCIAL
- Target sectors
- health, manufacturing, information-technology, insurance, construction, retail, finance, hospitality, transport, professional-services
- Target regions
- united states of america, hong kong, taiwan, brazil, egypt, japan
- Detection rules
- 9
- Indicators of compromise
- 7
Malware and tooling in Cardiology Associates of Port Huron (Port Huron Heart
Malware and tooling: Orova ransomware, OROVA ransomware operation
How Cardiology Associates of Port Huron (Port Huron Heart works
Cardiology Associates of Port Huron, P.C. (porthuronheartcenter.com), a Michigan-based cardiovascular practice operating since 1974, was breached by the Orova ransomware group. Over 144.00 GB of patient data (244,215 files) was exfiltrated during a June 2026 intrusion, with Orova posting an extortion notice on their Tor-hosted leak site on July 10, 2026, threatening public release of the stolen data unless a company representative initiated negotiations. As of August 6, 2026, the practice has not publicly disclosed or confirmed the incident, placing them at risk of HIPAA breach notification penalties.
On July 10, 2026, the Orova ransomware group added Cardiology Associates of Port Huron, P.C. (d/b/a Port Huron Heart Center) to their Tor-hosted data leak site, claiming responsibility for an intrusion that resulted in the theft of 144.00 GB of data (244,215 files). The group posted the extortion notice with the statement: "The full leak will be published soon, unless a company representative contacts us via the channels provided," indicating that negotiations had not yet begun as of the posting date.
Cardiology Associates of Port Huron is a physician-owned partnership founded in 1974, headquartered at 1222 10th Avenue, Port Huron, Michigan. The practice employs 3 interventional cardiologists, a vascular interventionist, an electrophysiologist, and 3 non-invasive cardiologists supported by nurse practitioners, physician assistants, registered nurses, and exercise physiologists. It operates 7 satellite clinics spanning north into Michigan's Thumb region and south to Algonac.
Orova is an emerging ransomware group first observed in May 2026, classified by WatchGuard Technologies as a "Data Broker" operation employing double-extortion tactics (data theft plus encryption), with an additional tactic of "free data leaks" — publicly releasing stolen data without payment as a coercive measure. The group has claimed 24+ victims across 6 countries (United States — 13 victims, Hong Kong — 5, Taiwan — 4, with single victims in Brazil, Egypt, and Japan), targeting diverse sectors including healthcare (4 confirmed victims — the most-hit sector), manufacturing, finance, IT, insurance, and construction.
Orova's observed attack chain includes: purchasing compromised credentials from infostealer markets (~24% of victims had domain credentials detectable in infostealer markets prior to attack per Hudson Rock/ransomware.live data), exploiting unpatched vulnerabilities in public-facing applications, deploying spear-phishing campaigns, conducting internal reconnaissance and Active Directory profiling, exfiltrating sensitive data before encryption, identifying and destroying/corrupting backups to eliminate recovery options, and deploying mass encryption across file servers, domain controllers, email servers, and operational systems.
The group operates a sophisticated extortion infrastructure including a Tor-hosted leak site (mll5ddmdzgiq2siv3qnocmmqyiigfpajtc663xtf32qtp6weycyx2hyd.onion), a separate Tor-hosted negotiation/chat portal (ns7y6bxawualjj5rpo5num6syejd7hgaowrndk3r4duxu2iyinzv6hid.onion), and a Tox encrypted messaging ID for direct victim communication. Data exfiltration volumes documented across victims range from 15.90 GB to 64.70 GB.
This breach exposes protected health information (PHI) from a cardiovascular practice, potentially including patient names, medical records, clinical histories, diagnoses, treatment plans, insurance information, Social Security numbers, billing data, and other personally identifiable information (PII). As a HIPAA-covered entity, Cardiology Associates is subject to mandatory breach notification requirements under HIPAA/HITECH, including notification to affected individuals, the HHS Office for Civil Rights (OCR), and potentially local media. The HHS OCR has intensified ransomware enforcement in 2026, issuing four settlements totaling $1,165,000 in April 2026 alone, and has now completed 20 ransomware-related enforcement actions.
No specific technical IOCs (malware hashes, C2 server IPs, encrypted file extensions, ransom note filenames) have been publicly released for Orova as of this report, as the group is too new for detailed reverse-engineering reports from major cybersecurity vendors. Monitoring of Orova's Tor infrastructure, continued victim tracking, and credential exposure assessments remain the primary detection vectors.
MITRE ATT&CK techniques used in TL-2026-1916
Credential Access
Collection
Discovery
T1018 Remote System Discovery; T1046 Network Service Discovery; T1069 Permission Groups Discovery; T1087 Account Discovery
Lateral Movement
Initial Access
T1078 Valid Accounts; T1190 Exploit Public-Facing Application; T1566 Phishing
Command and Control
T1095 Non-Application Layer Protocol
Execution
Impact
T1485 Data Destruction; T1490 Inhibit System Recovery
Exfiltration
T1567 Exfiltration Over Web Service
defense-impairment
Affected products and versions in Cardiology Associates of Port Huron (Port Huron Heart
- Cardiology Associates of Port Huron, P.C. — Healthcare Services (Cardiovascular Medicine)
Vulnerable versions: All systems and patient data prior to June 2026
Remediation for Cardiology Associates of Port Huron (Port Huron Heart
Patches
- Patch all public-facing applications against known CVEs (VPN, RDP, Exchange, web servers)
- Apply critical security updates within 24-hour SLA for internet-facing systems
- Disable unused remote access services (RDP if not required, legacy VPN protocols)
Immediate actions
- Notify affected patients under HIPAA breach notification requirements within 60 days
- Engage incident response and forensic investigation team
- Reset all credentials and enforce MFA across all systems
- Report to law enforcement (FBI IC3, CISA, HHS OCR)
- Isolate compromised systems and preserve evidence for forensic analysis
- Monitor Orova Tor leak site and Tox channels for data publication
Workarounds
- Restrict outbound Tor network access from corporate environments
- Block known Orova Tor leak site domains on network proxies and DNS filters
- Implement application allowlisting to prevent unauthorized executables
- Enable Windows Event Logging (4688 process creation, 4104 PowerShell) for forensic visibility
Longer-term hardening
- Implement EDR/XDR with behavioral ransomware detection across all endpoints
- Deploy network segmentation to limit lateral movement and blast radius
- Implement immutable/air-gapped backup strategy with offline and offsite copies
- Establish continuous credential monitoring for infostealer market exposure
- Conduct regular ransomware tabletop exercises and incident response drills
- Deploy 24/7 SOC monitoring with threat hunting for ransomware precursors
- Implement comprehensive vendor risk management for third-party access
Timeline of Cardiology Associates of Port Huron (Port Huron Heart
- Orova ransomware group first observed in the wild by threat intelligence platforms; begins posting victims to Tor leak site
- Orova gains initial access to Cardiology Associates of Port Huron network (estimated, based on DataBreaches.net reporting of patient data stolen in June); initial access likely via purchased infostealer credentials, unpatched vulnerability, or phishing
- Internal reconnaissance and Active Directory profiling performed to map network topology, identify domain administrators, and locate sensitive patient data repositories
- Approximately 144.00 GB of patient data exfiltrated from Cardiology Associates systems to Orova-controlled infrastructure before encryption deployment
- Backup systems identified, targeted, and corrupted/destroyed to prevent recovery without paying ransom; mass encryption deployed across file servers, domain controllers, and email servers
- Orova posts extortion notice on Tor-hosted leak site threatening public release of 144.00 GB of stolen patient data unless company representative initiates negotiations
- FalconFeeds.io and ransomware.live publicly identify Orova after group posts 24 victims on Tor leak site in single bulk announcement; Orova's total claimed victims reaches 24+ across US, Hong Kong, Taiwan, Brazil, Egypt, and Japan
- BreachSense and DeXpose index the incident; WatchGuard ransomware tracker confirms Orova has claimed 24+ victims across 6 countries; FalconFeeds.io publishes bulk alert
- DataBreaches.net publishes detailed report; Cardiology Associates of Port Huron has not publicly disclosed or confirmed the incident; 60-day HIPAA notification clock begins for breach affecting 500+ individuals
Sources cited for Cardiology Associates of Port Huron (Port Huron Heart
- Cardiology Associates of Port Huron Remains Silent After Alleged Hack — DataBreaches.net
- OROVA Ransomware Attack on Cardiology Associates — DeXpose
- Cardiology Associates of Port Huron Data Breach — BreachSense
- WatchGuard Ransomware Tracker — OROVA
- Orova Ransomware Breaches Five Hong Kong Firms — TechTimes
- ransomware.live — Orova Tracking Page
- HHS OCR Settles Four HIPAA Security Rule Ransomware Investigations — HHS.gov
- FalconFeeds.io — Orova Bulk Alert (24 Victims)
Detection coverage for TL-2026-1916
As of 2026-08-06, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1916 across Splunk SPL, Microsoft KQL and Sigma, covering 7 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.