
Chaos and M3rx Ransomware Groups Escalate Attacks on US Healthcare and Legal Sectors
As of September 30, 2026, the Chaos and M3rx ransomware groups have launched targeted double-extortion campaigns against US-based organizations, threatening the release of hundreds of gigabytes of sensitive data.
Executive Takeaway — TL;DR
- Category:
- Threat Intelligence
- Severity:
- Critical
- Actor Type:
- Ransomware Group
- Geography:
- USA
- Confidence:
- Confirmed
- Source:
- Dexpose Intel Feeds
- Read Time:
- 4 min
Executive Summary
On September 30, 2026, intelligence feeds confirmed a surge in aggressive ransomware activity targeting critical infrastructure in the United States. The Chaos ransomware group has initiated a high-pressure campaign against the Carolina Asthma & Allergy Center, while the M3rx group has successfully breached the South Florida law firm Otero Geeza Law, P.A. Both incidents utilize classic double-extortion tactics, where threat actors exfiltrate sensitive data before encrypting systems to force payment.
Threat Analysis
The current landscape reflects a shift toward rapid-fire extortion. The Chaos group has issued a 24-hour ultimatum to the Carolina Asthma & Allergy Center, threatening to leak 290 GB of patient and administrative records. Simultaneously, M3rx has claimed the theft of 82.5 GB of data from Otero Geeza Law, P.A. These attacks highlight a persistent trend where threat actors prioritize the exfiltration of personally identifiable information (PII) and protected health information (PHI) to maximize leverage over victims who are legally obligated to protect such data.
Technical Details
Both groups are employing sophisticated multi-stage attack chains. Initial access is frequently gained through credential harvesting or the exploitation of unpatched edge-facing vulnerabilities. Once inside the network, the actors move laterally to identify backup servers. Recent reports indicate that emerging gangs are increasingly prioritizing the destruction of backups to eliminate the possibility of recovery without paying the ransom. The exfiltration phase involves the use of automated tools to siphon data to cloud storage providers, followed by the deployment of custom encryption binaries that bypass traditional signature-based detection.
Attribution Assessment
Chaos and M3rx are identified as cybercriminal syndicates operating with a focus on financial gain. While their infrastructure is often obfuscated through multi-hop proxies, their operational patterns—specifically the use of public leak sites to host stolen data—align with established Ransomware-as-a-Service (RaaS) models. These groups are likely composed of distributed affiliates who leverage shared malware kits to conduct independent campaigns.
Implications
The targeting of healthcare and legal entities suggests a strategic focus on sectors with low tolerance for downtime and high regulatory pressure regarding data privacy. The 24-hour deadline imposed by the Chaos group is particularly concerning, as it leaves minimal time for incident response teams to contain the breach or negotiate, effectively forcing a binary choice between payment and public data exposure.
Recommendations
Organizations must prioritize the implementation of immutable, off-site backups that are air-gapped from the primary network. Furthermore, security teams should enforce strict multi-factor authentication (MFA) across all remote access points and conduct regular threat hunting exercises to identify indicators of compromise (IoCs) associated with RaaS affiliates. Given the rapid escalation of these attacks, incident response plans should be updated to include pre-negotiated legal and forensic support to handle extortion demands effectively.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Ransomware Surge: Emperador and SafePay Lead Record-Breaking September 2026 Extortion Wave

Ransomware Surge: Emperador and SafePay Groups Escalate Attacks on US and European Infrastructure

