INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Ransomware Attack Targets Healthcare Entities
| 2026-08-29 13:45 CRITICAL HIGH RANSOMWARE & EXTORTION CRITICAL INFRASTRUCTURE & OT
Executive Summary
AI-generated
The recent surge in targeted cyber operations against healthcare entities has raised concerns about the vulnerability of sensitive data breaches and potential exploitation by threat actors. Interim Healthcare, a US-based provider of medical services, was attacked twice - once in August and again on September 10, with each incident involving different groups claiming responsibility for the breach. The attacks have resulted in significant financial losses, including over $128,000 paid to victims in January following a ransomware attack in Winona County. Furthermore, Interim Healthcare of Amarillo and Interim Healthcare of Pampa were also targeted, highlighting the need for robust cybersecurity measures to protect against such incidents.
Technical Mitigations AI-generated
* Implement a robust incident response plan, including procedures for responding to ransomware attacks and containing the breach.
* Conduct regular security audits and vulnerability assessments to identify potential entry points for threat actors.
* Use encryption and secure communication protocols (e.g. HTTPS) when transmitting sensitive patient data over the internet.
* Regularly update and patch software applications, operating systems, and firmware to prevent exploitation of known vulnerabilities.
* Consider investing in a cybersecurity information and event management system (SIEM) to monitor and analyze security-related data from various sources.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
po•••••.org
da•••••.net
in•••••.exchange
ww•••••.com
Em•••••.pdf
rs•••••.png
se•••••.pdf
ar•••••.html
we•••@In•••.•••
AI Podcast (EN) detail_available
detail_listen_ai (EN)
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
ShinyHuntersShinyHuntersTeamPCPTeamPCP
QilinQilin
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
FIVE_EYES
FIVE_EYES
governmentgovernment
healthhealth
Incident Timeline
October 31, 2025
Threat actors used phishing and malware to compromise Interim HealthCare systems, potentially exposing sensitive patient data.
between October 31, 2025
Doctor Alliance breached Interim HealthCare's portal between October 31, 2025, and November 17, 2025.
November 17, 2025
The same incident description and substitute notice are also available on the Interim Healthcare of Amarillo and Interim Healthcare of Pampa websites.
Click on any entity below to view its context and source!
organisation
the Interim Healthcare of Amarillo
The same incident description and substitute notice are also available on the Interim Healthcare of Amarillo and Interim Healthcare of Pampa websites.
organisation
Interim Healthcare of Pampa
The same incident description and substitute notice are also available on the Interim Healthcare of Amarillo and Interim Healthcare of Pampa websites.
November 2025
The threat actors, Anubis and Genesis, claim to have acquired significant amounts of data from Interim HealthCare entities.
Click on any entity below to view its context and source!
organisation
the Interim HealthCare Oklahoma City
Nor is there any notice on the Interim HealthCare Oklahoma City website as of publication.
organisation
DataBreaches
DataBreaches submitted an inquiry to Interim HealthCare-Oklahoma City via their contact form and will update this post if a reply is received.
organisation
Interim Healthcare’s
Less than one week after Genesis claimed to have attacked the Oklahoma City franchise, another group — Anubis — claims that while Genesis hit Oklahoma, they hit Interim Healthcare’s corporate headquarters.
data_breach
1 TB
The threat actor claims to have more than 1 TB of data, including patient records and internal documents.
data_breach
530 GB
Anubis claims to have acquired 530 GB of data comprising 335,093 files.
data_breach
335,093 files
Anubis claims to have acquired 530 GB of data comprising 335,093 files.
Jan. 22, 2026
The county's decision to pay $128,539.57 in ransom to restore its computer network was made after consultation with the local cybersecurity team.
Click on any entity below to view its context and source!
tactic
Ransomware
The county said it negotiated and paid $128,539.57 with assistance from its insurance carrier after ransomware was detected on its computer network Jan. 22, 2026.
>
>
> Officials said the decision was made after consultation with the county’s cybersecurity team and was intended to support the full resumption of county services and protection of personal information.
financial
$128,539.57 county
The county said it negotiated and paid $128,539.57 with assistance from its insurance carrier after ransomware was detected on its computer network Jan. 22, 2026.
>
>
> Officials said the decision was made after consultation with the county’s cybersecurity team and was intended to support the full resumption of county services and protection of personal information.
February 25, 2026
Doctor Alliance breached the Lubbock franchise's portal between October 31, 2025, and November 17, 2025.
April 7
Ransomware groups have been targeting Interim HealthCare entities.
Click on any entity below to view its context and source!
tactic
Ransomware
A second ransomware attack was detected April 7.
May 12
Threat actors used social media to notify affected individuals in writing on May 12.
August 10
Genesis threat actors targeted Interim HealthCare Oklahoma City on August 10.
Click on any entity below to view its context and source!
industry
Healthcare
Then, on August 10, Genesis threat actors claimed responsibility for an attack on Interim HealthCare Oklahoma City.
organisation
Genesis
Then, on August 10, Genesis threat actors claimed responsibility for an attack on Interim HealthCare Oklahoma City.
Sunday, August 16, 2026
Threat actors used a previously unknown vulnerability in Interim HealthCare's database management system to gain unauthorized access and delete sensitive data on Sunday, August 16.
Click on any entity below to view its context and source!
target_region
United States
Sunday, August 16, 2026 12:53:58 PM (UTC-05:00) Eastern Time (US & Canada)
>
>
> was deleted without being read on Wednesday, August 26, 2026 3:58:33 PM (UTC-05:00) Eastern Time (US & Canada).
target_region
Canada
Sunday, August 16, 2026 12:53:58 PM (UTC-05:00) Eastern Time (US & Canada)
>
>
> was deleted without being read on Wednesday, August 26, 2026 3:58:33 PM (UTC-05:00) Eastern Time (US & Canada).
organisation
US & Canada
Sunday, August 16, 2026 12:53:58 PM (UTC-05:00) Eastern Time (US & Canada)
>
>
> was deleted without being read on Wednesday, August 26, 2026 3:58:33 PM (UTC-05:00) Eastern Time (US & Canada).
August 16, 2026
The incident has raised concerns among other franchises that may have been affected by the same breach.
Click on any entity below to view its context and source!
organisation
Media/Press
Their response?
> To: wehearyou
>
> Subject: Media/Press inquiry about multiple data breach claims
>
>
Wednesday, August 26, 2026 3:58:33 PM
Threat actors used a previously unknown vulnerability in Interim HealthCare's database management system to target multiple entities on Sunday, August 16.
Click on any entity below to view its context and source!
target_region
United States
Sunday, August 16, 2026 12:53:58 PM (UTC-05:00) Eastern Time (US & Canada)
>
>
> was deleted without being read on Wednesday, August 26, 2026 3:58:33 PM (UTC-05:00) Eastern Time (US & Canada).
target_region
Canada
Sunday, August 16, 2026 12:53:58 PM (UTC-05:00) Eastern Time (US & Canada)
>
>
> was deleted without being read on Wednesday, August 26, 2026 3:58:33 PM (UTC-05:00) Eastern Time (US & Canada).
organisation
US & Canada
Sunday, August 16, 2026 12:53:58 PM (UTC-05:00) Eastern Time (US & Canada)
>
>
> was deleted without being read on Wednesday, August 26, 2026 3:58:33 PM (UTC-05:00) Eastern Time (US & Canada).
August 26, 2026
Threat actors used phishing to target Interim HealthCare entities.
Click on any entity below to view its context and source!
organisation
DataBreaches
© 2009 – 2026 DataBreaches.net and DataBreaches LLC.
organisation
MDN
>
> Final-recipient: RFC822; [email protected]
>
> Disposition: automatic-action/MDN-sent-automatically; deleted
They probably meant to reply that they take privacy and security very seriously.
organisation
Signal
Contact me on Signal: Dissent.73
News Tip?
August 28, 2026
Threat actors used phishing to compromise Interim HealthCare systems, allowing them to gain unauthorized access and potentially exfiltrate sensitive data.
2026/08/28
The incident reported on August 28, 2026, involves Meta Glasses being used to film someone.
Click on any entity below to view its context and source!
organisation
Meta Glasses
Did someone wearing Meta Glasses film you today?
August 29, 2026
The incident affected approximately 2,071 individuals.
Click on any entity below to view its context and source!
organisation
Interim HealthCare
The covered entity (CE), Interim Healthcare of Lubbock, reported that it was notified by its business associate (BA) that it experienced a breach of its network that affected approximately 2,071 individuals.
organisation
BA
The covered entity (CE), Interim Healthcare of Lubbock, reported that it was notified by its business associate (BA) that it experienced a breach of its network that affected approximately 2,071 individuals.
organisation
HHS
West Texas notified HHS that 2,071 patients were affected, while the Amarillo franchise notified HHS that 666 patients were affected.
organisation
Amarillo
West Texas notified HHS that 2,071 patients were affected, while the Amarillo franchise notified HHS that 666 patients were affected.
organisation
CE
The CE notified HHS, the media, and the affected individuals.
2026/08/29
The incident has raised concerns about potential targeted attacks on Interim HealthCare entities.
2026/08/29
Two different groups have recently attacked Interim HealthCare entities.
Click on any entity below to view its context and source!
threat_actor
ShinyHunters
Category:Government Sector
## Post navigation
← UK: HIV charity has ‘sensitive’ health data stolen
McKesson is investigating a cybersecurity incident after ShinyHunters claims patient data theft →
### Leave a Reply Cancel reply
Your email address will not be published.
* Star Health’s public record: A data breach, a ₹3.39-crore fine, 13,000 ombudsman complaints — and still no accounting for the policyholder
* McKesson is investigating a cybersecurity incident after ShinyHunters claims patient data theft
*
Grab it at:
### Recent Posts
* McKesson is investigating a cybersecurity incident after ShinyHunters claims patient data theft
*
organisation
Click2Mail
Category:Commentaries and AnalysesHealth DataHIPAAMiscellaneousU.S.
## Post navigation
← Star Health’s public record: A data breach, a ₹3.39-crore fine, 13,000 ombudsman complaints — and still no accounting for the policyholder
SCOOP: Some Click2Mail customers will soon be receiving notification of a data security incident →
### Leave a Reply Cancel reply
Your email address will not be published.
data_breach
13,000 ombudsman complaints
Category:Commentaries and AnalysesHealth DataHIPAAMiscellaneousU.S.
## Post navigation
← Star Health’s public record: A data breach, a ₹3.39-crore fine, 13,000 ombudsman complaints — and still no accounting for the policyholder
SCOOP: Some Click2Mail customers will soon be receiving notification of a data security incident →
### Leave a Reply Cancel reply
Your email address will not be published.
* Star Health’s public record: A data breach, a ₹3.39-crore fine, 13,000 ombudsman complaints — and still no accounting for the policyholder
* McKesson is investigating a cybersecurity incident after ShinyHunters claims patient data theft
*
financial
$128 Stolen / Extorted Funds
Winona County paid more than $128K following January ransomware attack
* UK:
Winona County paid more than $128K following January ransomware attack.
Title: Winona County paid more than $128K following January ransomware attack - DataBreaches.
Winona County paid more than $128,000 following a January ransomware attack, according to a county news release.
threat_actor
TeamPCP
* Swarm of 700 AI bots went rogue in hacking attack
* Manchester Airports Group confirms cyber attack exposed customer emails, phone numbers and vehicle details
* Two Alleged ‘TeamPCP’ Hackers Arrested in Australia
* NSA to host a hacker reunion in bid to rebuild secretive unit
* US takes down alleged Chinese hacking tools used against Federal Reserve, DOJ and Senate
* National Kidney Registry allegedly hacked by DireWolf ransomware group
### !
organisation
Interim HealthCare
Two different groups have recently attacked Interim HealthCare entities.
organisation
Anubis
Image 1: Directory of Folders and FIles Leaked by Anubis
_Directory of Folders and Files Leaked by Anubis, Allegedly from Interim Healthcare Headquarters.
organisation
Directory of Folders
Image 1: Directory of Folders and FIles Leaked by Anubis
_Directory of Folders and Files Leaked by Anubis, Allegedly from Interim Healthcare Headquarters.
organisation
Interim Healthcare Headquarters
Image 1: Directory of Folders and FIles Leaked by Anubis
_Directory of Folders and Files Leaked by Anubis, Allegedly from Interim Healthcare Headquarters.
organisation
South Plains Rural Health Services
PEAR leaks data allegedly exfiltrated from South Plains Rural Health Services while SPRHS remains silent
* SCOOP: Some Click2Mail customers will soon be receiving notification of a data security incident
*
organisation
SPRHS
PEAR leaks data allegedly exfiltrated from South Plains Rural Health Services while SPRHS remains silent
* SCOOP: Some Click2Mail customers will soon be receiving notification of a data security incident
*
organisation
ATF
HIV charity has ‘sensitive’ health data stolen
* Qilin claimed they attacked the ATF.
organisation
DHS
Meta Reaches $16.68 Billion Settlement Over Social Media Harms To Children
* DHS bids to vacuum up voter registration, history from all 50 states
*
[Image 1: RSS feed: Recent Posts on PogoWasRight.org]( Posts on PogoWasRight.org
* Meta Reaches $16.68 Billion Settlement Over Social Media Harms To Children
* DHS bids to vacuum up voter registration, history from all 50 states
*
financial
$16.68 Settlement
Meta Reaches $16.68 Billion Settlement Over Social Media Harms To Children
* DHS bids to vacuum up voter registration, history from all 50 states
*
[Image 1: RSS feed: Recent Posts on PogoWasRight.org]( Posts on PogoWasRight.org
* Meta Reaches $16.68 Billion Settlement Over Social Media Harms To Children
* DHS bids to vacuum up voter registration, history from all 50 states
*
organisation
RSS
[Image 1: RSS feed: Recent Posts on PogoWasRight.org]( Posts on PogoWasRight.org
* Meta Reaches $16.68 Billion Settlement Over Social Media Harms To Children
* DHS bids to vacuum up voter registration, history from all 50 states
*
[Image 2: RSS feed: Recent Posts on PogoWasRight.org]( Posts on PogoWasRight.org
* California Legislature Advances Bill to Strengthen Deletion Rights
*
organisation
The Doctor Alliance
The Doctor Alliance breach by the threat actor“Kazu” was previously reported by DataBreaches inNovember 2025 and was updated a week later after Kazu claimed to have hacked them a second time and raised the ransom demand.
organisation
DataBreaches inNovember 2025
The Doctor Alliance breach by the threat actor“Kazu” was previously reported by DataBreaches inNovember 2025 and was updated a week later after Kazu claimed to have hacked them a second time and raised the ransom demand.
data_breach
2025 inNovember
The Doctor Alliance breach by the threat actor“Kazu” was previously reported by DataBreaches inNovember 2025 and was updated a week later after Kazu claimed to have hacked them a second time and raised the ransom demand.
organisation
California Legislature Advances
[Image 2: RSS feed: Recent Posts on PogoWasRight.org]( Posts on PogoWasRight.org
* California Legislature Advances Bill to Strengthen Deletion Rights
*
organisation
Apple’s Next AirPods May Have Cameras
Discord Says It Hasn’t Been Served With A Subpoena Over GTA 6 Leaks Yet: ‘We’ll Evaluate The Validity And Scope Before Responding’
* Apple’s Next AirPods May Have Cameras.
organisation
the Privacy Implications
Your Office Isn’t Ready for the Privacy Implications
###
organisation
InterLock
A search of the dark web reveals that it was InterLock who claimed responsibility for the April attack and dumped a great deal of data.
organisation
the Privacy Implications
*
Your Office Isn’t Ready for the Privacy Implications
*
Tactical Metrics
Metrics
financial
128,000
Stolen / Extorted Funds
Click for context!
Winona County paid more than $128K following January ransomware attack
* UK:
Winona County paid more than $128K following January ransomware attack.
Title: Winona County paid more than $128K following January ransomware attack - DataBreaches.
Winona County paid more than $128,000 following a January ransomware attack, according to a county news release.
Metrics
data_breach
13,000
Ombudsman Complaints
…sesHealth DataHIPAAMiscellaneousU.S.
## Post navigation
← Star Health’s public record: A data breach, a ₹3.39-crore fine, 13,000 ombudsman complaints — and still no accounting for the policyholder
SCOOP: Some Click2Mail customers will soon be re…
* Star Health’s public record: A data breach, a ₹3.39-crore fine, 13,000 ombudsman complaints — and still no accounting for the policyholder
* McKesson is investigating a cybersecurity incident after ShinyHunters claims patient data theft
*
Metrics
financial
16,680,000,000
Settlement
Meta Reaches $16.68 Billion Settlement Over Social Media Harms To Children
* DHS bids to vacuum up voter registration, history from all 50 states
*
[Image 1: RSS feed: Recent Posts on PogoWasRight.org]( Posts on PogoWasRight.org
* Meta Reaches $16.68 Billion Settlement Over Social Media Harms To Children
* DHS bids to vacuum up voter registration, history from all 50 states
*
Metrics
data_breach
2,025
Innovember
The Doctor Alliance breach by the threat actor“Kazu” was previously reported by DataBreaches inNovember 2025 and was updated a week later after Kazu claimed to have hacked them a second time and raised the ransom demand.
Metrics
data_breach
1
Tb
The threat actor claims to have more than 1 TB of data, including patient records and internal documents.
Metrics
data_breach
530
Gb
Anubis claims to have acquired 530 GB of data comprising 335,093 files.
Metrics
data_breach
335,093
Files
Anubis claims to have acquired 530 GB of data comprising 335,093 files.
Metrics
financial
128,540
County
The county said it negotiated and paid $128,539.57 with assistance from its insurance carrier after ransomware was detected on its computer network Jan. 22, 2026.
>
>
> Officials said the decision was made after consultation with the county’s cybe…
Intelligence Sources
Data Breaches
2026-08-29
Data Breaches
2026-08-28
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Reset / Delete
Incident Version History
CURRENT VERSION
Last Updated: 2026-08-30T07:31
Comprehensive Tactical Telemetry
Highly Correlated Entities
32x
organisation
Identified Entity
US & Canada
entity
18x
timeline
Temporal Reference
Sunday, August 16, 2026
date
6x
attribution
Attributing Entity
Manchester Airports Group
authority
5x
industry
Targeted Sector
Government
sector
4x
target region
Target Country
United States
country
3x
source region
Origin Country
Australia
country
2x
tactic
Cyber Operation Type
Data Breach
tactic
2x
threat actor
APT Group
ShinyHunters
actor
Contextual Telemetry
Context Block
17 METRICS
general metric
Bitcoin
30
bitcoin
financial
Stolen / Extorted Funds
128,000
$
general metric
Individuals
2,071
individuals
general metric
Crore
3
crore
data breach
Ombudsman Complaints
13,000
ombudsman complaints
malware
Malware Payload
Qilin
tool
tactic
MITRE ATT&CK Technique
T1593.001 - Social Media
technique
financial
Settlement
16,680,000,000
settlement
general metric
States
50
states
general metric
Patients
666
patients
data breach
Innovember
2,025
innovember
general metric
Gta
6
gta
data breach
Tb
1
tb
data breach
Gb
530
gb
data breach
Files
335,093
files
general metric
Ai Bots
700
ai bots
financial
County
128,540
county
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.