Find notable cyber news and cases, enriched with sources, timelines, and signals.

Medical institution in North America hit by data theft breach

Incident
First reported
Last updated
Happening score
H score 26
1 unique sources, 1 articles

Summary

Hide ▲

A North American medical institution suffered a REDCap breach that enabled InfiniteRed deployment and sensitive-data theft, leaving the network compromised for more than a year. GTIG attributed the intrusion to UNC6508 and tied the initial compromise to September 2023. The attackers used a credential-harvesting component, a backdoor, and email-based exfiltration through a legitimate compliance-rule feature. Google notified affected organizations in the U.S. and Canada after identifying the activity.

Related Happenings

Google hit by network compromise

Incident
H score42 First: 14.07.2026 09:19 Last: 14.07.2026 09:19 Sources 1

About this happening: Google confirmed a June 2025 compromise of one corporate Salesforce instance, and attackers took largely public business contact data before access was cut off. Th...

INFINITERED REDCap backdoor and credential harvester

Malware Activity
H score26 First: 15.06.2026 22:44 Last: 15.06.2026 22:44 Sources 1

About this happening: The INFINITERED malware was deployed on REDCap servers to preserve access, steal credentials, and operate as a backdoor inside compromised research environments. It trojan...

UNC6508 China-linked REDCap espionage campaign

Campaign
H score39 First: 15.06.2026 17:00 Last: 15.06.2026 17:00 Sources 1

How related: A China-linked espionage campaign targeted exposed REDCap servers to deploy the InfiniteRed malware and steal sensitive data from a medical institution in North America.

About this happening: UNC6508 ran a China-linked espionage campaign against exposed REDCap servers used by North American medical, academic, and military research networks. The operatio...

Timeline

  1. 15.06.2026 17:00 2 articles · 1mo ago

    Medical institution in North America hit by data theft breach

    Initial Disclosure

    The intrusion appears to have started in September 2023 when attackers probed older, vulnerable REDCap versions and established access to the medical institution’s environment. The victim remained compromised without detection while the operators prepared later malware and exfiltration mechanisms.

    Show sources