
Chaos and M3rx Ransomware Groups Escalate Attacks on US Professional and Healthcare Sectors
Recent intelligence confirms a surge in double-extortion attacks by Chaos and M3rx, targeting US-based healthcare and legal entities. These groups are leveraging stolen data to force rapid ransom payments.
Executive Takeaway — TL;DR
- Category:
- Threat Intelligence
- Severity:
- Critical
- Actor Type:
- Cybercriminal
- Geography:
- USA
- Confidence:
- Confirmed
- Source:
- Microsoft MSTIC
- Read Time:
- 4 min
Executive Summary
As of October 1, 2026, the threat landscape is witnessing a significant uptick in aggressive double-extortion campaigns. Within the last 48 hours, the Chaos ransomware group has targeted the Carolina Asthma & Allergy Center, while the M3rx group has successfully breached the South Florida law firm Otero Geeza Law, P.A. These incidents highlight a persistent trend of targeting sensitive personal and administrative data to maximize leverage against victims.
Threat Analysis
The current operational tempo of ransomware groups like Chaos and M3rx reflects a broader trend observed throughout 2026, where over 1,000 organizations were impacted globally in August alone. These groups utilize dedicated leak sites to publish exfiltrated data, a hallmark of the double-extortion model. By targeting sectors with high regulatory and privacy requirements—such as healthcare and legal services—these actors ensure that the pressure to pay is immediate and severe.
Technical Details
In the attack against Carolina Asthma & Allergy Center, the Chaos group claims to have exfiltrated 290 GB of sensitive patient and administrative data. Similarly, M3rx has reported the theft of 82.5 GB of data from Otero Geeza Law, P.A. These attacks typically involve the initial compromise of network perimeters, followed by lateral movement to identify high-value file shares. Once data is exfiltrated, the actors deploy encryption payloads to lock production systems, effectively halting business operations while simultaneously threatening public disclosure of the stolen information.
Attribution Assessment
Chaos and M3rx are identified as financially motivated cybercriminal syndicates. Unlike nation-state actors focused on espionage, these groups prioritize rapid monetization. Their operational patterns—including the use of public leak sites and short-fuse negotiation windows—align with the tactics of other active groups like Audit-Team and the recently emerged Emperador, which has been active in the Asia-Pacific region since August 2026.
Implications
The continued success of these groups suggests that current defensive postures in the professional services and healthcare sectors remain insufficient against modern extortion tactics. The threat of data leakage is now as critical as the operational downtime caused by encryption, forcing organizations to reconsider their incident response strategies to include robust data loss prevention and offline backup verification.
Recommendations
- Implement strict network segmentation to limit lateral movement during an initial breach.
- Conduct regular, offline backups of critical data and test restoration procedures frequently.
- Deploy advanced endpoint detection and response (EDR) solutions to identify anomalous data exfiltration patterns.
- Establish a pre-vetted incident response plan that includes legal and public relations counsel to manage the complexities of double-extortion scenarios.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Chaos and M3rx Ransomware Groups Escalate Attacks on US Healthcare and Legal Sectors

Ransomware Surge: Emperador and SafePay Lead Record-Breaking September 2026 Extortion Wave

