NPMHA A.I CyberSecurity Scoring
NPMHA
Company Information
Website:http://socstc.org
Employees number:94
Number of followers:0
NAICS:62133
Industry Type:Mental Health Care
Homepage:socstc.org
NPMHA Risk Score (AI oriented)
Between 750 and 799
NPMHAMental Health Care
Updated:
09/03/2026
09/03/2026
755/1000
Fair
Baa
NPMHA Global Score (TPRM)
xxxx
NPMHAMental Health Care
Score locked

NPMHAFair
Current Score
755Baa (FAIR)
01000
1 incidents
-73 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JULY 2026
760
JUNE 2026
759
MAY 2026
757
APRIL 2026
757
MARCH 2026
755
FEBRUARY 2026
754
JANUARY 2026
753
DECEMBER 2025
752
NOVEMBER 2025
822
Ransomware
01 Nov 2025 • NPMHA
Non-profit mental health provider and Educational facility for autistic children: North Korean Hackers Using Medusa Ransomware in Attacks on U.S. Healthcare Sector
North Korean Hackers Deploy Medusa Ransomware in U.S. Healthcare Attacks
749
CRITICAL-73
ACENON1772051729
North Korean Hackers Deploy Medusa Ransomware in U.S. Healthcare Attacks
A joint investigation by Symantec and the Carbon Black Threat Hunter Team has revealed that North Korean state-sponsored hackers, specifically the Lazarus Group, are targeting U.S. healthcare organizations and non-profits with Medusa ransomware. The attacks, linked to the Reconnaissance General Bureau (RGB) of North Korea’s government, blend espionage with financially motivated cybercrime.
Medusa, a ransomware-as-a-service (RaaS) operation active since 2023, operates under a double-extortion model encrypting data and threatening to leak or auction stolen information if ransoms go unpaid. While Lazarus has previously used Maui and Play ransomware, recent evidence confirms its shift to Medusa in campaigns since November 2025. Victims include a non-profit mental health provider and an educational facility for autistic children, with average ransom demands reaching $260,000.
A Lazarus subgroup, Stonefly (aka Andariel), is suspected of involvement. The group, historically focused on espionage, has increasingly turned to ransomware attacks on healthcare targets over the past five years. The U.S. Department of Justice has indicted Rim Jong Hyok, a North Korean national allegedly tied to the RGB, for his role in these attacks, which are believed to fund broader espionage operations.
Symantec and Carbon Black have tracked 366 Medusa ransomware attacks, though the group claims over 500 victims, including more than 40 healthcare organizations. Indicators of compromise (IoCs) and tools used in the campaigns have been shared to aid detection. While attribution to a specific Lazarus subgroup remains unclear, the evidence firmly ties the attacks to the broader Lazarus collective.
INCIDENT DETAILS -
TYPE
MOTIVATION
DATA BREACH
REFERENCES
OCTOBER 2025
822
SEPTEMBER 2025
822
AUGUST 2025
822
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for NPMHA ??
What was NPMHA's A.I Rankiteo Cyber Score in June 2026 ??
What was NPMHA's A.I Rankiteo Cyber Score in May 2026 ??
What was NPMHA's A.I Rankiteo Cyber Score in April 2026 ??
What was NPMHA's A.I Rankiteo Cyber Score in March 2026 ??
What was NPMHA's A.I Rankiteo Cyber Score in February 2026 ??
What was NPMHA's A.I Rankiteo Cyber Score in January 2026 ??
What was NPMHA's A.I Rankiteo Cyber Score in December 2025 ??
What was NPMHA's A.I Rankiteo Cyber Score in November 2025 ??
What was NPMHA's A.I Rankiteo Cyber Score in October 2025 ??
What was NPMHA's A.I Rankiteo Cyber Score in September 2025 ??
What was NPMHA's A.I Rankiteo Cyber Score in August 2025 ??
What is the average per-incident point impact on NPMHA's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with NPMHA ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view NPMHA's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?