Doommageddon is a newly tracked operation, first observed on July 1, 2026, with only four claimed victims to date and one in the past 30 days, suggesting either a low-volume or early-stage campaign. Its claimed targeting so far concentrates on healthcare (two of four victims, including a pharmacy chain and a hospital), with single hits against a financial services firm and a consumer services company, and geographic focus falls on Brazil and Paraguay. The group is described in its own materials as running a double extortion model, meaning it claims to exfiltrate data before encryption and threatens publication to pressure payment, though no independent technique catalogue is yet available for this actor. Given the short operating window and small sample size, current activity should be read as an emerging, low-frequency threat rather than an established high-volume operation.