Incident analysis
SMCare was listed by Panzer ransomware, a group with 53 victims recorded in this database. The listing appeared on the group's leak site on September 28, 2026.
Sector context. Healthcare organisations are high-value ransomware targets because patient data is extremely sensitive, regulatory penalties for breaches are severe, and operational downtime can threaten patient safety — all factors that increase ransom payment pressure.
Panzer typically follows a double extortion model: data is exfiltrated from the victim's systems before files are encrypted, so the victim faces two demands at once — pay to restore access, and pay to keep stolen data unpublished. The leak site, where this listing appeared, is the lever for the second demand.