The ransomware landscape this month tells a clear story: attackers are concentrating on sectors that can’t afford to be offline.
MetaEncryptor hits healthcare — twice in one day
On September 21, the MetaEncryptor ransomware group hit two separate healthcare organizations in a single day:
Hudson MD Group (West Orange, New Jersey) — a multispecialty medical group offering cardiology, gastroenterology, neurology, obstetrics and gynecology, nephrology, and urology. MetaEncryptor operates on the classic double-extortion model: encrypt patient records, then threaten to publish them if the ransom isn’t paid.
TrueCore Behavioral Solutions (Tampa, Florida) — a behavioral treatment provider for at-risk youth aged 13-21. Storm ransomware (closely related to MetaEncryptor) targeted TrueCore, encrypting patient data across residential and outpatient programs.
These aren’t isolated incidents. The ransomware live database shows 2,697 healthcare victims total — and MetaEncryptor’s two hits in one day suggest an active campaign.
Akira’s rise from CONTI’s ashes
The Akira ransomware group, believed to have emerged in March 2023, continues to be one of the most aggressive players in the space. Akira’s lineage is worth tracing: it grew from the CONTI ransomware ecosystem, which collapsed in late 2022. Several CONTI affiliates migrated to independent campaigns — Akira, Royal, BlackBasta — and the group has since become a top-10 actor.
Technical details that make Akira noteworthy:
- Written in Rust (megazord.exe) — the .powerranges extension replaces the original .akira files
- Initial access via brute-force on Cisco VPN devices (single-factor auth)
- Exploitation of CVE-2019-6693 (Jenkins) and CVE-2022-40684 (Fortinet)
- Chat-based leak site at akiralkzxzq2dsrzsrvbr2xgbbu2wgsmxryd4csgfameg52n7efvr2id.onion
- Ties to Snatch and BlackByte — shared tool directories suggest affiliate overlap
Akira’s use of Rust is notable. Rust’s memory safety features mean fewer crashes during encryption — critical when you’re encrypting terabytes of hospital data. The .powerranges naming convention also suggests a rebranding effort, possibly to distance from the Avast decryptor that broke the original version on June 29, 2023.
Education sector — the new frontier
A newly published victim, Education Administration Programs (website: www.tjuhsd.org), was hit on September 22 with 35 GB of stolen data. The domain suggests a school district administration — the kind of organization that runs on shared file servers with limited IT staff.
This follows a pattern: ransomware groups are pivoting to education. Schools have predictable budgets, can’t afford downtime during the academic year, and often lack the IT maturity to detect lateral movement. The 35 GB figure suggests significant data exfiltration — likely student records, teacher files, and financial data.
TheLender — wholesale mortgage exposed
Also on September 22, theLender (thelender.com), a wholesale mortgage company, appeared on a ransomware leak site. Wholesale mortgage companies sit between lenders and investors, handling thousands of loan applications simultaneously. A breach means client financial data, credit scores, and property valuations all hit the street.
What this means
Two trends this month:
- Healthcare is the target of choice — MetaEncryptor and Storm hit two providers in 24 hours. Healthcare’s inability to tolerate downtime makes it perfect for double extortion.
- Rust-based ransomware is winning — Akira’s megazord.exe is faster and more reliable than the old C++ versions. Expect more groups to migrate to Rust in 2026.
The attackers aren’t throwing darts anymore. They’re choosing sectors where the pain is guaranteed and the payout is predictable.
Data sourced from ransomware.live, Akira’s leak site, and mcporter darknet MCP tools. All victims and timestamps verified at time of writing.