~/f4n6 $ grep -r "Ransomware: lockbit5 named huisartsencentrumkleiniterson.nl (NL)" ./investigations/ --include="*.md"

Ransomware: lockbit5 named huisartsencentrumkleiniterson.nl (NL)

Jeff Davies 05 Sep 2026 3 min read

1. Executive summary

On 2026-09-04, the ransomware operator branding as "lockbit5" listed the Dutch primary-care medical practice Huisartsencentrum Klein Iterson (huisartsencentrumkleiniterson.nl, NL) as a victim on its leak site, indexed by Ransomware.live. The listing is a leak-site claim only: no technical detail on initial access, malware, encryption, or exfiltration volume is present in the source material, and the actor "lockbit5" has no MITRE ATT&CK profile — attribution to any historical LockBit operation is unconfirmed. The victim is a healthcare provider, not a financial services entity, so direct exposure to EMEA FS clients is limited to any third-party, data-sharing, or supply-chain relationship with this practice or its parent organisation. No CISA-KEV exploitation state, CVSS score, or vulnerability is associated with this item; this is a victim-naming event, not a disclosed CVE.

2. Regulatory framing

No specific DORA/NIS2 article is directly engaged by this item. The source contains only a leak-site victim listing with no facts (e.g. a confirmed incident at a client, a named ICT third-party provider relationship, or a classified major incident) that would trigger a distinctive obligation under the articles in scope. Clients should re-assess if corroborating detail emerges linking this victim to their own ICT third-party or supply-chain footprint.

3. Technical analysis & attack chain

What is confirmed (single-sourced): The Ransomware.live index records that the group "lockbit5" published huisartsencentrumkleiniterson.nl as a victim on 2026-09-04. The victim is described as a Healthcare Services provider operating in primary medical care in the Netherlands. Ransomware.live states it indexes only publicly visible leak-site posts and does not access underlying stolen data; a leak screenshot is referenced in the listing metadata.

What is not in the source: No initial access vector, exploited CVE or component, malware family or capabilities, persistence mechanism, C2 infrastructure, lateral movement, encryption behaviour, exfiltration evidence, ransom note text, or data-sample content is present. No claimed data volume or deadline is recorded. The listing does not state whether this is a double-extortion claim (data theft with publication threat) or an encryption claim.

Attribution caveat: The actor name "lockbit5" has no MITRE ATT&CK profile in our verified reference data. Treat any implied connection to the historical LockBit/LockBit 3.0 operations as unconfirmed. The "5" suffix naming pattern is consistent with post-takedown rebranding observed in the ransomware ecosystem, but no source here corroborates that link — do not act on it.

Confidence caveat: This entire item rests on a single source (the Ransomware.live index of the leak-site post). Leak-site claims are routinely inflated, duplicated, or fabricated for reputational pressure; victim organisations have also been named erroneously. Verify before enforcement — confirm with the victim or via independent reporting before treating the compromise as established fact.

4. Mitigation & containment

No technical containment is possible from this item — there is no vulnerability, malware sample, or infrastructure to act against. Actions are relationship-based:

P1 — within 24h

  • If your organisation has any data-sharing, referral, payroll, insurance-claims, or platform relationship with huisartsencentrumkleiniterson.nl or its parent: identify what data categories and connection methods (S2S VPN, API credentials, shared mail relays, document exchange) exist, and assess whether patient or employee data of your organisation could be in the victim's estate.
  • Rotate any shared credentials, API keys, or VPN pre-shared keys associated with that relationship pending confirmation of the incident.

P2 — within 72h

  • Screen any inbound correspondence claiming to represent the practice against fraud/social-engineering patterns; compromise-and-extortion events are frequently followed by payment-diversion or invoice-fraud attempts against the victim's counterparties.
  • If a client-side data-processing relationship exists, request a written incident status from the practice's DPO or security contact.

P3 — within 7 days

  • Monitor the leak site index for a data sample or deadline update; re-assess exposure if stolen data is published.
  • No patch, version pin, or configuration change is indicated by this item.

5. Indicators of compromise

No indicators of compromise available in the source material. The listing references a leak screenshot but provides no extractable atomic indicators (no hashes, domains beyond the victim's own legitimate domain, IPs, or file artefacts). The victim domain huisartsencentrumkleiniterson.nl is legitimate infrastructure and must not be treated as an IOC.

6. Detection

Insufficient indicators to author detection rules.

7. Sources

  • Ransomware.live — "Victim: huisartsencentrumkleiniterson.nl – lockbit5" — https://www.ransomware.live/id/aHVpc2FydHNlbmNlbnRydW1rbGVpbml0ZXJzb24ubmxAbG9ja2JpdDU= — 2026-09-04

8. Adverse Trace position

Low direct severity for EMEA financial services clients: this is a single-sourced leak-site naming of a Dutch primary-care practice, with no technical detail, no corroborated attribution (the actor "lockbit5" has no MITRE profile — treat as unconfirmed), and no demonstrated link to any client's environment. The risk to clients is conditional and third-order: exposure exists only where a data or connectivity relationship with this practice is in place, and even then the compromise itself is unverified. We are treating this as watch-list only — no client action beyond the relationship checks in §4 is warranted. Adverse Trace will monitor for corroborating reporting, a published data sample, or victim confirmation, and will re-issue if the claim is substantiated or if a client-side connection is identified.


Read the original source →

Published via PulseTrace — Adverse Trace threat intelligence.

Post this to LinkedIn
Formatting is converted automatically — headings, bullets, a link back & hashtags. Paste straight in.
J
Jeff Davies