HomeIntelligenceBrief
BREACH BRIEF🟠 High Breach

Anubis Ransomware Deploys Data‑Wipe Mode, Hits U.S. Healthcare Provider with 293 GB Theft

Anubis ransomware, newly rebranded from Sphinx, breached Singing River Health System, exfiltrating 293 GB of patient data and offering a destructive “wipe mode.” The incident underscores the need for SOC 2‑aligned phishing defenses, patch management, and verified backup processes.

LiveThreat™ Intelligence · 📅 July 17, 2026· 📰 fortra.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
5 sector(s)
Actions
4 recommended
📰
Source
fortra.com

Anubis Ransomware Deploys “Wipe Mode” and Targets U.S. Healthcare Providers

What Happened — The Anubis ransomware‑as‑a‑service (RaaS) group, rebranded from “Sphinx” in late 2024, encrypts files with a “.anubis” extension and can optionally invoke a “wipe mode” that overwrites files to zero‑byte size. In July 2026 the group breached Mississippi‑based Singing River Health System, exfiltrating 293 GB of patient data (PII, medical records, bank details) and threatening publication. Entry vectors reported include spear‑phishing emails and exploitation of the CitrixBleed 2 vulnerability (CVE‑2025‑5777).

Why It Matters for Compliance & Audit Readiness

  • SOC 2 CC6.1 (Logical Access) and CC7.2 (Incident Management) require documented controls against phishing and unpatched vulnerabilities; Anubis shows the cost of gaps.
  • Continuous evidence of security‑awareness training and phishing‑simulation results is essential audit proof that the organization mitigates the most common ransomware entry point.
  • Demonstrable, tested backup and recovery processes satisfy SOC 2 CC5.2 (Backup) and provide a defensible posture when ransomware attempts data‑wipe attacks.

Who Is Affected – Primarily U.S. healthcare providers; secondary targets include manufacturing, construction, legal, and financial services.

Recommended Actions

  • Map phishing‑email controls and vulnerability‑patch management to SOC 2 CC6.1/CC7.2 and collect continuous monitoring evidence.
  • Verify that all critical systems are patched for CVE‑2025‑5777; document the patch‑status as audit evidence.
  • Run a security‑awareness simulation, record participation, and remediate gaps before the next audit window.
  • Validate that immutable, offline backups exist and can be restored within RTO/RPO targets.

Source: Fortra Blog – Anubis ransomware

Technical Notes – Attack vectors: spear‑phishing (malicious attachments/links) and exploitation of CitrixBleed 2 (CVE‑2025‑5777). Payload adds “.anubis” to encrypted files; optional wipe mode overwrites data to zero bytes. Stolen data includes SSNs, DOB, health‑insurance numbers, diagnostic images, and banking details.

📰 Original Source
https://www.fortra.com/blog/anubis-ransomware

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Security Awareness

Phishing and social engineering are a people-and-policy problem.

The Verisq AI Trust Operations platform pairs Security Awareness Training with policy adoption tracking, so human-risk controls are documented and audit-ready.

Explore the Verisq AI Trust Operations platform →