Anubis and Global Secret Group Ransomware Claims Raise Fresh Alarm for Healthcare and Energy Sectors + Video

Listen to this Post

Featured Image

A New Wave of Ransomware Claims

Ransomware gangs do not need to shut down an entire company to create fear. Sometimes, the first warning is much quieter: a victim’s name suddenly appears on an underground leak site or in a threat-intelligence feed. From there, uncertainty takes over—what was accessed, what was stolen, whether systems were encrypted, and whether sensitive information could eventually be published.

On August 3, 2026, two separate ransomware claims drew attention from the cybersecurity community. Threat intelligence monitoring attributed one claim to Anubis, which allegedly added BLACKBURN’S Physicians Pharmacy, Inc. to its victim list. A second claim attributed to Global Secret Group named Novum Energy.

At this stage, these should be treated as ransomware-group claims rather than independently confirmed breaches. The available information does not establish how attackers allegedly entered either organization, whether ransomware was successfully deployed, how much data may have been accessed, or whether any information was actually exfiltrated.

That distinction matters. A name appearing on a ransomware leak list is an important warning signal, but it is not by itself proof that every allegation made by an attacker is accurate.

BLACKBURN’S Physicians Pharmacy Becomes the Focus of an Anubis Claim

The first reported victim is BLACKBURN’S Physicians Pharmacy, Inc., a long-established healthcare provider. According to BLACKBURN’S own history, the organization began as an independent community pharmacy in 1936 and has since expanded into medical equipment, supplies, pharmaceuticals, respiratory services, home accessibility, and other healthcare-related services.

blackburnsmed.com

+1

That breadth makes the allegation particularly noteworthy from a cybersecurity perspective. Modern healthcare organizations frequently hold information that is valuable not only because of its financial worth, but because it can contain highly sensitive personal and operational information.

BLACKBURN’S says it operates pharmacy services, durable medical equipment, respiratory services, medical supplies, rehabilitation technology, wound-care services, and other healthcare programs.

blackburnsmed.com

Its website also states that the organization maintains a corporate HIPAA privacy and security program and has invested in compliance controls designed to protect customers and support regulatory requirements.

blackburnsmed.com

Why a Healthcare Target Is Especially Sensitive

A ransomware incident involving a healthcare provider can have consequences that extend far beyond ordinary business disruption.

Healthcare organizations can potentially handle patient identifiers, insurance information, prescriptions, medical documentation, billing records, employee information, provider information, and other confidential material.

Even when attackers fail to encrypt systems, alleged theft of information can still become the central weapon in an extortion campaign.

This is why modern ransomware has increasingly evolved from a simple “encrypt the files and demand payment” model into a broader extortion business.

Anubis Has a History of Targeting Healthcare

The Anubis ransomware operation has been associated with attacks against healthcare organizations as well as engineering, construction, and professional-services targets. Security reporting has described Anubis as a ransomware-as-a-service operation that combines encryption with data theft and extortion.

Dark Reading

+1

Recent ransomware tracking also shows multiple healthcare-related organizations appearing among Anubis-linked victims.

That history makes the BLACKBURN’S allegation particularly relevant, although it does not independently confirm that BLACKBURN’S was compromised.

The crucial question is therefore not simply whether the organization’s name appeared on a threat actor’s list, but whether forensic evidence, company disclosure, regulatory filings, or other reliable sources eventually confirm the incident.

The Second Claim: Novum Energy

The second organization named in the supplied threat-intelligence report is Novum Energy, which was allegedly added to the victim list of the Global Secret Group.

Novum Energy describes itself as a global energy trading and logistics group originating in Houston, Texas. Its business involves oil and refined-product supply, trading, logistics, risk management, and related services across multiple international markets.

novumenergy.com

+1

The company says it operates across the United States, Latin America, Europe, and Asia-Pacific, giving it a considerably different risk profile from a regional healthcare provider.

novumenergy.com

This makes the two claims interesting when viewed together.

One involves healthcare and potentially sensitive patient-related information.

The other involves energy trading, logistics, commercial operations, and potentially sensitive corporate and financial information.

Global Secret Group Has Been Listing Victims

Independent ransomware tracking provides additional context around the Global Secret Group claim.

Ransomware monitoring data has listed Novum Energy under Global Secret Group, alongside other organizations attributed to the same operation.

RansomLook

Other recent reporting has documented Global Secret Group listings involving companies in sectors ranging from finance and business services to technology and infrastructure. Those reports also emphasize an important limitation: a ransomware leak-site listing represents an attacker allegation and does not automatically establish that the claimed compromise has been independently verified.

GalaxyWarden

+1

This pattern suggests that Global Secret Group is actively using public victim listings as part of its extortion strategy.

Why These Two Claims Matter Together

At first glance, BLACKBURN’S Physicians Pharmacy and Novum Energy have little in common.

One is connected to healthcare and medical services.

The other operates in global energy trading and logistics.

Yet that difference illustrates an important reality about ransomware in 2026: attackers are not limited to a single industry.

The common denominator is valuable access.

Healthcare organizations possess sensitive personal and medical information.

Energy companies possess commercially valuable information, operational records, contracts, trading data, financial information, and potentially sensitive logistics details.

For ransomware operators, both categories can provide leverage.

The Real Weapon Is Often the Data

The most damaging part of a ransomware attack may not be encryption.

Data theft can create a much longer period of uncertainty.

If attackers allegedly steal information before encryption, they can threaten to publish it even after systems are restored.

That creates a second pressure point for the victim.

A company can recover servers.

It can rebuild endpoints.

It can restore backups.

It cannot simply “restore” information that has already been copied by an attacker.

Leak-Site Claims Are Designed to Create Pressure

Ransomware leak sites serve a psychological purpose as much as a technical one.

Publishing a

A countdown can increase urgency.

Sample files can provide credibility.

Threatening to publish more information can place additional pressure on executives, legal teams, insurers, and incident-response specialists.

This is why organizations should not automatically assume that a leak-site listing means the attacker has complete control over the victim.

The listing itself is part of the extortion mechanism.

What We Still Do Not Know

There are currently major unanswered questions surrounding both claims.

There is no confirmed public evidence establishing the initial access vector.

There is no verified public figure for the amount of data allegedly stolen.

There is no confirmed number of affected individuals.

There is no independently established ransomware family deployed against either organization.

There is also no reliable public evidence in the supplied material proving that encrypted systems were actually taken offline.

These details should remain clearly separated from confirmed facts.

BLACKBURN’S Operational Exposure Could Be Broad

BLACKBURN’S describes a service model extending beyond a traditional retail pharmacy.

The organization provides medical equipment, pharmacy services, respiratory products, rehabilitation technology, wound-care supplies, home accessibility services, and other healthcare-related support.

blackburnsmed.com

That means a serious cyber incident could theoretically affect multiple operational workflows rather than a single pharmacy application.

Order processing, billing, customer communications, delivery operations, medical equipment coordination, and internal administrative systems can all become relevant during an incident.

However, there is currently no verified evidence showing that any particular BLACKBURN’S system was affected.

Novum Energy Presents a Different Risk Equation

Novum

The company says it manages physical energy supply and trading operations and works with suppliers, buyers, logistics partners, and customers across multiple regions.

novumenergy.com

+1

A successful compromise of such an organization could potentially create exposure involving contracts, transaction records, operational schedules, counterparties, financial information, logistics documentation, and internal communications.

Again, these are potential categories based on the organization’s business activities—not evidence that such information was stolen in this alleged incident.

The Supply-Chain Dimension Cannot Be Ignored

Energy trading and healthcare delivery are both highly interconnected.

A company rarely operates as a completely isolated digital island.

Healthcare providers interact with insurers, manufacturers, distributors, pharmacies, technology vendors, laboratories, payment processors, and government systems.

Energy companies interact with traders, producers, shipping companies, storage facilities, financial institutions, customers, regulators, and technology providers.

A compromised third party can therefore become a pathway into a much broader ecosystem.

Ransomware Operators Understand This Connectivity

Modern extortion groups increasingly benefit from the interconnected nature of corporate environments.

A single compromised identity can provide access to cloud applications.

A compromised remote-access account can expose internal systems.

A vendor account can become a bridge between otherwise separated environments.

This is why identity security has become just as important as traditional endpoint protection.

The Importance of Identity Security

Organizations can deploy advanced antivirus systems and still suffer devastating breaches if attackers obtain legitimate credentials.

Multifactor authentication reduces this risk, although not every MFA implementation offers the same protection.

Phishing-resistant authentication, strong privileged-access controls, conditional access, session monitoring, and rapid credential revocation can significantly improve resilience.

The objective is simple: make stolen credentials less useful.

Backups Are Still Essential

Backups remain one of the most important ransomware defenses.

But having backups is not enough.

Backups must be isolated from production environments, protected against unauthorized deletion, regularly tested, and capable of supporting real recovery operations.

An organization that discovers its backups are corrupted or encrypted at the same time as its production systems may find itself with very few options.

Recovery Testing Separates Theory From Reality

Many organizations know how to create a backup.

Far fewer regularly test whether they can restore an entire business process.

A recovery exercise should answer practical questions.

How quickly can critical applications return?

Which systems must be restored first?

Who has authority to make emergency decisions?

Can employees operate manually if core systems are unavailable?

Can customers and patients still receive essential services?

These questions become extremely important during ransomware incidents.

Deep Analysis

Command 1: Treat the Claim as an Alert, Not a Verdict

The first defensive command is conceptual: classify both incidents as unverified ransomware claims until reliable evidence confirms them.

That prevents analysts from turning an attacker-controlled statement into an established fact.

Command 2: Establish the Timeline

Security teams should reconstruct authentication events, endpoint alerts, VPN activity, cloud sign-ins, privilege changes, and unusual data-transfer events.

The goal is to determine when suspicious activity began—not simply when the ransomware claim appeared online.

Command 3: Hunt for Identity Abuse

Investigators should examine privileged accounts, dormant accounts, service accounts, recently created accounts, impossible-travel events, repeated authentication failures, and suspicious MFA activity.

Identity compromise is frequently the bridge between an external attacker and internal resources.

Command 4: Examine Remote Access

VPN infrastructure, remote-management platforms, remote desktop services, virtual application environments, and administrative gateways deserve immediate review.

Unexpected authentication from unfamiliar locations or devices should be treated as a high-priority investigation signal.

Command 5: Review Endpoint Telemetry

Endpoint detection and response systems can help identify suspicious process execution, credential access, persistence mechanisms, lateral movement, and unusual encryption activity.

The investigation should focus on behavioral evidence rather than simply searching for a specific ransomware filename.

Command 6: Review Cloud Activity

Cloud environments can become extremely valuable targets because attackers may not need to deploy traditional malware if they can abuse legitimate cloud credentials.

Security teams should examine unusual downloads, mass file access, abnormal OAuth activity, new application permissions, suspicious mailbox rules, and unexpected administrative changes.

Command 7: Search for Data Exfiltration

If data theft is suspected, organizations should review outbound traffic, cloud storage activity, archive creation, unusual compression operations, and large transfers from sensitive systems.

The objective is to determine whether data actually left the environment.

Command 8: Preserve Evidence

Organizations should avoid destroying evidence during emergency remediation.

Disk images, memory captures where appropriate, authentication logs, firewall records, endpoint telemetry, cloud audit logs, and relevant email evidence can become critical to understanding the incident.

Command 9: Separate Encryption From Exfiltration

Investigators should determine whether there are signs of encryption, data theft, or both.

A company may experience data theft without ransomware encryption.

Conversely, ransomware encryption may occur without evidence of successful exfiltration.

The distinction matters for both response and notification decisions.

Command 10: Investigate Privilege Escalation

Attackers who move from a compromised workstation to administrative infrastructure can dramatically increase the blast radius of an intrusion.

Security teams should therefore examine changes involving privileged groups, domain administrators, cloud administrators, backup operators, and other high-value accounts.

Command 11: Protect Backup Infrastructure

Backup credentials should be reviewed immediately when ransomware activity is suspected.

Attackers frequently understand that backup destruction can make victims more vulnerable to extortion.

Backup systems therefore deserve the same security attention as production servers.

Command 12: Rotate High-Risk Credentials

Credentials associated with compromised systems should be rotated according to a controlled incident-response plan.

Particular attention should be paid to privileged accounts, service accounts, API credentials, cloud access keys, VPN accounts, and third-party integrations.

Command 13: Examine Third-Party Connections

Both healthcare and energy organizations depend heavily on external partners.

Security teams should identify whether compromised credentials or integrations could provide access to suppliers, customers, contractors, or managed-service environments.

Command 14: Monitor for Secondary Extortion

If the claims are legitimate, attackers may attempt additional pressure through direct communications, leak-site updates, sample publication, or contact with customers and partners.

Monitoring should therefore continue after the initial containment phase.

Command 15: Verify Before Publishing Conclusions

Threat intelligence teams should distinguish clearly between:

The attacker claims the company was compromised.

and

“The company was confirmed to have suffered a ransomware attack.”

Those sentences are not interchangeable.

Command 16: Watch for Confirmation

The most important next development will be confirmation or denial from the affected organizations, regulators, law-enforcement agencies, cybersecurity investigators, or other authoritative sources.

Until then, the responsible position is to report the claims without overstating them.

Command 17: Consider the Human Impact

Cybersecurity reporting can sometimes reduce an incident to company names and technical indicators.

But healthcare incidents can potentially affect patients.

Energy incidents can potentially affect commercial partners and operational networks.

The human and economic consequences should remain part of the analysis.

Command 18: Understand the Extortion Economy

Ransomware groups increasingly operate like businesses.

They identify targets.

They obtain access.

They steal information.

They encrypt systems when useful.

They negotiate.

They publish victims when negotiations fail.

The victim-list announcement is therefore only one component of a larger criminal business model.

Command 19: Expect Multiple Pressure Points

An organization facing ransomware may simultaneously deal with technical recovery, legal obligations, regulatory requirements, public relations, customer communication, insurance questions, and potential litigation.

The faster a company establishes accurate facts, the better positioned it becomes to manage these competing pressures.

Command 20: Build Resilience Before the Attack

The strongest ransomware response begins months or years before an incident.

MFA, segmentation, EDR, secure backups, privileged-access management, email security, vulnerability management, employee awareness, incident-response planning, and continuous monitoring all reduce the potential impact.

What Undercode Say:

Two Different Industries, One Ransomware Problem

The most important lesson from these claims is the diversity of modern ransomware targets.

Healthcare and energy have completely different operational environments, but both possess information that attackers can monetize.

The Claims Are Serious but Not Yet Proof

The BLACKBURN’S and Novum Energy listings should be monitored closely, but reporting them as confirmed breaches without supporting evidence would go beyond the information currently available.

The responsible terminology is “claimed victim” or “alleged ransomware victim.”

BLACKBURN’S Deserves Particular Attention

BLACKBURN’S operates in a sector where confidentiality is exceptionally important.

Its own website describes a HIPAA privacy and security program, demonstrating that the organization recognizes the sensitivity of the information it handles.

blackburnsmed.com

If the claim is eventually confirmed, investigators will need to establish whether protected health information or other regulated data was involved.

The Potential Consequences Could Extend Beyond IT

A healthcare ransomware incident can disrupt more than computers.

It can interfere with ordering, billing, delivery, communications, equipment services, and other operational processes.

The severity therefore depends not only on how much data was allegedly stolen, but on which business functions were affected.

Novum Energy Represents Strategic Commercial Risk

Novum

Trading information, contracts, counterparties, logistics data, and financial records can be commercially sensitive even when they are not personally identifiable.

The consequences of losing such information could therefore involve competitive, financial, contractual, and reputational risks.

Global Secret Group Is Showing Persistent Activity

The appearance of Novum Energy alongside other organizations in ransomware monitoring data indicates continuing activity associated with Global Secret Group.

RansomLook

+1

That makes the allegation worth monitoring even before independent confirmation arrives.

Leak Sites Are Not Courtroom Evidence

Threat actors control their own websites and listings.

They can exaggerate.

They can publish outdated information.

They can claim victims they did not successfully compromise.

They can also possess genuine stolen information.

For that reason, leak-site information should be treated as intelligence requiring validation.

Evidence Changes the Story

A screenshot is not the same as forensic evidence.

A victim name is not the same as a confirmed data breach.

A sample file is stronger evidence than a name alone, but it still requires authentication.

Logs, forensic findings, and official disclosures provide much stronger confirmation.

Ransomware Has Become an Information War

The attackers are not merely attacking computers.

They are attacking confidence.

They want executives to fear publication.

They want customers to fear exposure.

They want employees to fear disruption.

They want investors and partners to question the organization’s security.

That psychological pressure is central to modern ransomware economics.

The First Hours Matter

When a ransomware claim appears, organizations should not wait for the story to become mainstream before investigating.

Early detection can reveal whether suspicious activity is ongoing.

Rapid containment can prevent attackers from moving deeper into the environment.

Healthcare Needs Defense in Depth

Healthcare organizations cannot depend on one security product.

They need layered protection around identities, endpoints, applications, networks, cloud systems, backups, and sensitive records.

A single defensive failure should not become a complete organizational compromise.

Energy Companies Need Similar Resilience

Energy trading and logistics companies also require layered security.

Their interconnected operations create numerous potential access points.

Vendor accounts, cloud systems, remote access, trading infrastructure, email, and third-party platforms can all become security concerns.

Data Exfiltration Should Be a Priority

The question “Were files encrypted?” is no longer enough.

Organizations must also ask:

Was information stolen?

If the answer is yes, recovery becomes only one part of the incident.

The organization must then determine what information was taken and whether legal or regulatory obligations have been triggered.

Backups Cannot Solve Data Theft

A perfect backup can restore an encrypted server.

It cannot erase a copy of stolen data sitting on an attacker’s infrastructure.

That is why modern ransomware defense must combine recovery capabilities with data-loss prevention and identity protection.

Public Transparency Requires Precision

Organizations should communicate what they know, what they do not know, and what they are investigating.

Overstating an incident can create unnecessary panic.

Understating it can damage trust later.

The best communication is factual, measured, and continuously updated.

Threat Intelligence Has a Critical Role

Threat intelligence can provide early warning.

But intelligence is most valuable when analysts correlate it with internal telemetry.

A ransomware listing becomes considerably more meaningful when it aligns with suspicious authentication events, endpoint alerts, unusual file transfers, or other forensic evidence.

The Next Stage Is Confirmation

For both BLACKBURN’S and Novum Energy, the next meaningful development will be independent confirmation, denial, or additional technical evidence.

Until then, the claims remain allegations.

Ransomware Pressure Will Continue

There is little reason to believe ransomware operators will abandon healthcare, energy, finance, manufacturing, or professional services.

These sectors contain exactly the type of information and operational dependency that extortion groups seek.

Organizations Must Assume Data Is Valuable

Even seemingly ordinary documents can become useful to attackers.

Invoices reveal relationships.

Contracts reveal customers.

Employee records reveal identities.

Emails reveal internal decisions.

Technical documents reveal infrastructure.

The cumulative value can be enormous.

The Real Security Objective Is Resilience

No organization can guarantee that it will never be targeted.

The more realistic objective is to make compromise difficult, detect it quickly, contain it effectively, recover reliably, and minimize the value of stolen information.

Anubis and Global Secret Group Demonstrate the Same Reality

Different ransomware operations may use different branding, infrastructure, and tactics.

But the underlying business model remains remarkably consistent.

Gain access.

Create leverage.

Demand payment.

Threaten exposure.

Ransomware Is No Longer Just an IT Problem

Executives, legal departments, compliance teams, communications professionals, insurers, law enforcement, and customers can all become part of the response.

Cybersecurity is therefore increasingly an organizational resilience problem rather than simply a technical problem.

The Claims Should Be Watched Closely

The BLACKBURN’S Physicians Pharmacy and Novum Energy allegations deserve continued monitoring.

But responsible reporting requires a line between intelligence and fact.

For now, that line remains important.

✅ BLACKBURN’S Physicians Pharmacy Is a Real Healthcare Organization

BLACKBURN’S confirms that BLACKBURN’S Physicians Pharmacy, Inc. is an established healthcare provider founded in 1936, offering pharmacy, medical equipment, respiratory, rehabilitation, and related services.

blackburnsmed.com

+1

✅ Novum Energy Is a Real Global Energy Company

Novum Energy confirms that it operates as an energy trading and logistics group originating in Houston, with activities spanning multiple international markets.

novumenergy.com

+1

❌ The Two August 3 Ransomware Claims Are Not Independently Confirmed

The supplied ThreatMon report and corroborating ransomware-tracking references establish that the organizations have been associated with ransomware listings or claims, but they do not independently prove the full allegations, the extent of compromise, or the amount of data allegedly stolen.

RansomLook

+1

Prediction

(-1) Ransomware Claims Will Continue Expanding Across Critical Sectors

The most likely near-term trend is continued targeting of organizations that combine valuable information with strong operational dependencies.

Healthcare providers will remain attractive because of sensitive patient and insurance information.

Energy companies will remain attractive because of commercially valuable data, international relationships, and operational complexity.

(-1) Extortion Will Remain the Central Weapon

Even when encryption is not publicly demonstrated, stolen-data claims can create enormous pressure.

Ransomware groups have learned that threatening disclosure can sometimes be more powerful than simply disabling computers.

(-1) Victim Lists Will Continue Appearing Before Confirmation

Threat actors are likely to continue publishing victim names rapidly.

That means cybersecurity teams and journalists will increasingly encounter allegations before companies have completed forensic investigations.

(+1) Better Monitoring Can Reduce the Damage

Organizations that combine strong identity controls, endpoint monitoring, network visibility, segmented infrastructure, and protected backups can significantly improve their ability to contain ransomware incidents.

(+1) Early Verification Will Become More Important

The cybersecurity industry is becoming better at distinguishing attacker claims from confirmed incidents.

More rigorous verification should eventually produce more reliable reporting and fewer exaggerated conclusions.

(-1) Healthcare Remains a High-Value Target

The potential sensitivity of healthcare information ensures that organizations such as BLACKBURN’S will remain attractive to extortion groups.

(-1) International Businesses Face Complex Exposure

Companies such as Novum Energy operate across multiple jurisdictions and business relationships, creating additional complexity when investigating and responding to cyber incidents.

(+1) Resilience Can Break the Extortion Cycle

Organizations that maintain tested recovery systems, strong identity controls, rapid detection, and effective incident-response procedures can reduce the leverage available to attackers.

(-1) The Final Impact Depends on Evidence Still Missing

For both reported victims, the most important facts remain unresolved.

Until forensic or official evidence becomes available, the severity of the alleged incidents cannot be reliably quantified.

(+1) The Cybersecurity Community Will Be Watching

If either organization confirms an incident, additional information could clarify the initial access method, affected systems, data exposure, operational disruption, and response measures.

Until then, the BLACKBURN’S and Novum Energy cases should remain classified as serious but unverified ransomware claims.

▶️ Related Video (78% Match):

🕵️‍📝Let’s dive deep and fact‑check.

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

References:

Reported By: x.com
Extra Source Hub (Possible Sources for article):
https://www.facebook.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon | 📺Youtube