CSIDB logo
Incident

National Health Fund

Incident posture

Attack window
Jun 2026
Location
-
Status
Unknown
CIA posture
Available to members
Updated
2026-09-08 19:35

Linked entities

Victim
National Health Fund
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Undetermined
Discovered
Jun 2026
Disclosed
Pending
Resolved
Pending

Summary

The National Health Fund was identified as a victim of the Pear ransomware group. The incident was listed on a ransomware victims site that provides brief summaries of recent compromises. The entry for this organization was marked as AI generated and indicated that no detailed information was available. It noted that the name is generic and used by multiple organizations, which limits attribution. The listing also included a timestamp indicating when the compromise was first observed by the monitoring service.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On June 10, 2026, the ransomware tracking site ransomware.live recorded an incident involving the National Health Fund. The entry indicates that the attack was discovered nine hours before the article’s timestamp, placing the discovery in the early morning of that day. The ransomware group associated with the incident is identified as Pear. The record includes a tag noting that the data is AI generated and marked as N/A. Additionally, the entry cautions that the name 'National Health Fund' is generic and is used by multiple organizations.

The source material does not provide any further specifics about the scope of the attack, such as which systems were affected or what data may have been compromised. No information is given regarding the ransom demand, the size of any data leak, or whether the victim has made a public statement. Likewise, the article contains no details about detection methods, containment steps, eradication efforts, or recovery actions taken by the National Health Fund. Consequently, the only verifiable facts from the provided source are the timing, the attributed ransomware group, and the note about the generic nature of the victim's name. Therefore, any narrative beyond these points would require additional sources not present in the current prompt.

Sources

Sources available to members: 1 source.

CSIDB