ctipilot.ch

Groupe 3R ransomware breach

incident · incident:groupe-3r-akira-2026 single-source-victim

Akira ransomware attack on Groupe 3R (Réseau Radiologique Romand) — 48 GB claimed; Swiss medical imaging.

Coverage timeline
4
first 2026-05-04 → last 2026-07-12
Peak priority
high
2 high · 2 notable
Sources cited
11
6 hosts
Sections touched
4
active-threats, updates, weekly-sector-patterns
Co-occurring entities
1
see Related entities below
ATT&CK techniques
4
pinned v19.1 · see below
2026-05-044 appearances2026-07-12

ATT&CK techniques

4 techniques observed across 3 entries — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.1 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1133External Remote Services×2

Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect to internal enterprise network resources from external locations. There are often remote service gateways that manage connections and credential authentication for these services. Services such as Windows Remote Management and VNC can also be used externally.

Evidence: 2026-05-10/groupe-3r-r-seau-radiologique-romand-akira-ransomware-claims · 2026-05-04/akira-ransomware-on-groupe-3r-20-swiss-medical-imaging-centr · ATT&CK page ↗

T1190Exploit Public-Facing Application×2

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-05-10/groupe-3r-r-seau-radiologique-romand-akira-ransomware-claims · 2026-05-04/akira-ransomware-on-groupe-3r-20-swiss-medical-imaging-centr · ATT&CK page ↗

Persistence TA0003

T1133External Remote Services×2

Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect to internal enterprise network resources from external locations. There are often remote service gateways that manage connections and credential authentication for these services. Services such as Windows Remote Management and VNC can also be used externally.

Evidence: 2026-05-10/groupe-3r-r-seau-radiologique-romand-akira-ransomware-claims · 2026-05-04/akira-ransomware-on-groupe-3r-20-swiss-medical-imaging-centr · ATT&CK page ↗

Exfiltration TA0010

T1567Exfiltration Over Web Service×3

Adversaries may use an existing, legitimate external Web service to exfiltrate data rather than their primary command and control channel. Popular Web services acting as an exfiltration mechanism may give a significant amount of cover due to the likelihood that hosts within a network are already communicating with them prior to compromise. Firewall rules may also already exist to permit traffic to these services.

Evidence: 2026-07-09/groupe-3r-akira-forensic-confirmation-darknet-publication · 2026-05-10/groupe-3r-r-seau-radiologique-romand-akira-ransomware-claims · 2026-05-04/akira-ransomware-on-groupe-3r-20-swiss-medical-imaging-centr · ATT&CK page ↗

Impact TA0040

T1486Data Encrypted for Impact×3

Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources. They can attempt to render stored data inaccessible by encrypting files or data on local and remote drives and withholding access to a decryption key. This may be done in order to extract monetary compensation from a victim in exchange for decryption or a decryption key (ransomware) or to render data permanently inaccessible in cases where the key is not saved or transmitted.

Evidence: 2026-07-09/groupe-3r-akira-forensic-confirmation-darknet-publication · 2026-05-10/groupe-3r-r-seau-radiologique-romand-akira-ransomware-claims · 2026-05-04/akira-ransomware-on-groupe-3r-20-swiss-medical-imaging-centr · ATT&CK page ↗

Story timeline

  1. 2026-07-12Healthcare across Switzerland and the UK saw ransomware confirmation, mailbox compromise and an insider-access clampdown this week
    weekly-sector-patternsHealthcare this week — Swiss radiology network confirms Akira attribution, Aargau psychiatric authority mailboxes phished, NHS England tightens insider access
  2. 2026-07-09Groupe 3R confirms Akira attribution and darknet publication of stolen data in its own forensic update
    updatesSwiss radiology network Groupe 3R confirms via its own forensics that Akira was behind its April attack and has published stolen data
  3. 2026-05-10Groupe 3R (Réseau Radiologique Romand) — Akira ransomware claims 48 GB; 20 imaging centres across seven Swiss cantons, second attack in twelve months
    active-threats
  4. 2026-05-04Akira ransomware on Groupe 3R — 20 Swiss medical-imaging centres across seven cantons; second cyberattack on the same operator within twelve months
    weekly-top-stories

Relationships explore in graph

Typed, source-stated connections from the entity registry — each edge cites the entry whose reporting establishes it.

attributed to

Where this entity is cited

  • weekly-top-stories1
  • active-threats1
  • updates1
  • weekly-sector-patterns1

Source distribution

  • attack.mitre.org4 (36%)
  • ictjournal.ch2 (18%)
  • swisscybersecurity.net2 (18%)
  • blick.ch1 (9%)
  • england.nhs.uk1 (9%)
  • groupe3r.ch1 (9%)

Co-occurring entities

Derived — referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

All cited sources (11)

Entries about Groupe 3R ransomware breach (4)

2026-07-12 · view entry permalink →

NOTABLENATOB1

Healthcare across Switzerland and the UK saw ransomware confirmation, mailbox compromise and an insider-access clampdown this week

Healthcare surfaced three ways this week, and the value of reading them together is that they cover the sector's external, identity and internal threat surfaces in a single window.

Externally, Groupe 3R — the Réseau Radiologique Romand, a Western-Swiss radiology network — confirmed in its own forensic report that the Akira ransomware operation was responsible for the intrusion that had twice disrupted it, and that stolen data had been published on Akira's darknet leak site (SwissCybersecurity.net, 2026-05-07). On the identity surface, Psychiatrische Dienste Aargau (PDAG), a cantonal psychiatric authority, had email accounts phished and abused as a spam relay (SwissCybersecurity.net, 2026-07-09). Internally, NHS England issued new controls after staff were found inappropriately accessing high-profile patients' records, tying repeat "snooping" to dismissal and potential prosecution (NHS England, 2026-07-11).

Why this belongs to the constituency's healthcare lens: two of the three are Swiss (a Romand radiology provider and an Aargau cantonal authority), and the third is a transferable governance lesson for any large healthcare data controller. Healthcare's threat model is not just ransomware on clinical systems — it is equally the mailbox identity that attackers abuse and the legitimate-but-excessive internal access that no perimeter control addresses.

Builds on: 2026-07-09/groupe-3r-akira-forensic-confirmation-darknet-publication · 2026-07-11/nhs-england-insider-patient-record-access-controls · 2026-07-09/pdag-aargau-email-account-compromise-spam-relay

synthesis12 Jul 23:32Zmulti-sourceOpen finding ↗

2026-07-09 · view entry permalink →

NOTABLEupdateNATOC2

Groupe 3R confirms Akira attribution and darknet publication of stolen data in its own forensic update

UPDATE · originally covered Groupe 3R (Réseau Radiologique Romand) — Akira ransomware claims 48 GB; 20 imaging centres across seven Swiss cantons, second attack in twelve months (2026-05-10)

Groupe 3R (Réseau Radiologique Romand), the network of 20 medical-imaging centres across seven Romandie cantons (Geneva, Vaud, Valais, Fribourg, Neuchâtel, Berne), has now confirmed through its own forensic investigation — not merely the attacker's leak-site claim — that the 30 April 2026 ransomware attack was carried out by Akira, and that stolen corporate and administrative documents have since been published on the darknet (SwissCybersecurity.net, 2026-07-07; ICTjournal.ch, 2026-07-06). This closes the attribution gap left open when Akira first listed the victim on 2026-05-08. The operator states medical data was encrypted (disrupting availability) but that no publication of medical data has been observed to date, while candidly acknowledging that whether medical data was also exfiltrated "may never be clarified with absolute certainty" — an unusually frank admission of incomplete forensic visibility that is itself the transferable lesson here.

Groupe 3R refused to pay the ransom, filed a criminal complaint with cantonal police on the attack date (forwarded to the Federal Public Prosecutor on 2026-05-12) and notified the Federal Office for Cybersecurity (BACS). As of this update all 20 centres are running on rebuilt, ISO-27001-partner infrastructure (RIS, PACS, telephony and teleradiology restored) but the referring-physician portal remained in security testing before redeployment — over two months post-incident. The activity is consistent with Akira's documented playbook: T1486 Data Encrypted for Impact (medical-data encryption), T1567 Exfiltration Over Web Service (darknet publication), typically preceded by edge-device / external-remote-service initial access.

incident09 Jul 12:25Zsingle-source · victim disclosureOpen finding ↗

2026-05-10 · view entry permalink →

HIGH

Groupe 3R (Réseau Radiologique Romand) — Akira ransomware claims 48 GB; 20 imaging centres across seven Swiss cantons, second attack in twelve months

Akira listed Groupe 3R on its dark-web leak site on approximately 2026-05-08, claiming an attack dated 2026-04-30 and threatening release of 48 GB including employee identity documents (passports, driving licences, national IDs), patient records (addresses, phone numbers, medical data), payment information, and signed NDAs (Groupe 3R victim statement, 2026-04-30 · ICTjournal.ch, 2026-05-06 · Blick.ch, 2026-05-07). Groupe 3R operates 20 medical-imaging centres across seven Romandie cantons (Vaud, Valais, Fribourg, Genève, Neuchâtel, Berne, and a further canton listed in the operator statement) — making this a direct Swiss critical-health-infrastructure incident. The operator confirmed the attack publicly via its own website on 2026-04-30, notified the Federal Office for Cybersecurity (BACS/OFCS), filed a criminal complaint, and explicitly stated it will not pay ransom. Legacy examination data remains inaccessible at the time of the public update; new examination data security has been restored on rebuilt infrastructure. Data-exfiltration was not confirmed by the victim; Akira's leak-site post asserts 48 GB exfiltrated. The operator's own statement notes this is its second cyberattack within twelve months and characterises the prior April 2025 incident as having involved different attackers and methodology.

Akira's documented playbook against European healthcare and small-to-mid enterprise targets emphasises edge-device initial access (Cisco ASA / FTD CVEs, Fortinet SSL-VPN CVEs, VMware ESXi authenticated RCE) and intermittent file-encryption to evade EDR file-IO heuristics; ATT&CK techniques observed across recent Akira incidents include T1190 Exploit Public-Facing Application, T1133 External Remote Services, T1486 Data Encrypted for Impact, and T1567 Exfiltration Over Web Service.

incident10 May 05:00Zmulti-sourceOpen finding ↗

Earlier coverage (1)