Payload Ransomware claims the hack of Royal Bahrain Hospital

2026-03-16T02:51:45Zeff3c934a68f100c7e7c2067301348c2289259d8d61915a0e97932f14d91af55
AI-assisted-malwareAVreconCISAHive0163InterpolPayload RansomwareSEO-poisoningSlopolyStorm-2561botnetcredential-harvestingdata-theftgoogle-chromehealthcareknown-exploited-vulnerabilitieslaw-enforcement-takedownphishingproxy-serviceransomwarespoofed-vpn

What happened

Multiple high-impact incidents reported: Payload Ransomware claims a breach of Royal Bahrain Hospital and publication of ~110 GB of stolen data. Starbucks disclosed a phishing-driven breach of its Partner Central portal impacting 889 employees. Microsoft-linked research attributes a credential-theft campaign to Storm-2561 using SEO-poisoned search results and spoofed Ivanti/Cisco/Fortinet VPN sites to harvest corporate logins. Law enforcement disrupted the SocksEscort proxy service tied to the AVrecon botnet (≈360,000 infected devices) and INTERPOL’s Operation Synergia III dismantled ~45,000 악

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
eff3c934a68f100c7e7c2067301348c2289259d8d61915a0e97932f14d91af55
Enrichment time
2026-03-16T02:51:45Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.