INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Ransomware Attack Targets Healthcare Entities

| 2026-08-29 13:45 CRITICAL HIGH RANSOMWARE & EXTORTION CRITICAL INFRASTRUCTURE & OT
Executive Summary
AI-generated
The recent surge in targeted cyber operations against healthcare entities has raised concerns about the vulnerability of sensitive data breaches and potential exploitation by threat actors. Interim Healthcare, a US-based provider of medical services, was attacked twice - once in August and again on September 10, with each incident involving different groups claiming responsibility for the breach. The attacks have resulted in significant financial losses, including over $128,000 paid to victims in January following a ransomware attack in Winona County. Furthermore, Interim Healthcare of Amarillo and Interim Healthcare of Pampa were also targeted, highlighting the need for robust cybersecurity measures to protect against such incidents.
Technical Mitigations AI-generated
* Implement a robust incident response plan, including procedures for responding to ransomware attacks and containing the breach. * Conduct regular security audits and vulnerability assessments to identify potential entry points for threat actors. * Use encryption and secure communication protocols (e.g. HTTPS) when transmitting sensitive patient data over the internet. * Regularly update and patch software applications, operating systems, and firmware to prevent exploitation of known vulnerabilities. * Consider investing in a cybersecurity information and event management system (SIEM) to monitor and analyze security-related data from various sources.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
po•••••.org
da•••••.net
in•••••.exchange
ww•••••.com
Em•••••.pdf
rs•••••.png
se•••••.pdf
ar•••••.html
we•••@In•••.•••
AI Podcast (EN) detail_available
detail_listen_ai (EN)
Intelligence distributed on:
Incident Link
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
ShinyHuntersShinyHuntersTeamPCPTeamPCP QilinQilin
Target & Sectors
NORTH_AMERICA NORTH_AMERICA FIVE_EYES FIVE_EYES governmentgovernment healthhealth
Incident Timeline
‎October 31, 2025
Threat actors used phishing and malware to compromise Interim HealthCare systems, potentially exposing sensitive patient data.
‎between October 31, 2025
Doctor Alliance breached Interim HealthCare's portal between October 31, 2025, and November 17, 2025.
‎November 17, 2025
The same incident description and substitute notice are also available on the Interim Healthcare of Amarillo and Interim Healthcare of Pampa websites.
organisation the Interim Healthcare of Amarillo
organisation Interim Healthcare of Pampa
‎November 2025
The threat actors, Anubis and Genesis, claim to have acquired significant amounts of data from Interim HealthCare entities.
organisation the Interim HealthCare Oklahoma City
organisation DataBreaches
organisation Interim Healthcare’s
data_breach 1 TB
data_breach 530 GB
data_breach 335,093 files
‎Jan. 22, 2026
The county's decision to pay $128,539.57 in ransom to restore its computer network was made after consultation with the local cybersecurity team.
tactic Ransomware
financial $128,539.57 county
‎February 25, 2026
Doctor Alliance breached the Lubbock franchise's portal between October 31, 2025, and November 17, 2025.
‎April 7
Ransomware groups have been targeting Interim HealthCare entities.
tactic Ransomware
‎May 12
Threat actors used social media to notify affected individuals in writing on May 12.
‎August 10
Genesis threat actors targeted Interim HealthCare Oklahoma City on August 10.
industry Healthcare
organisation Genesis
‎Sunday, August 16, 2026
Threat actors used a previously unknown vulnerability in Interim HealthCare's database management system to gain unauthorized access and delete sensitive data on Sunday, August 16.
target_region United States
target_region Canada
organisation US & Canada
‎August 16, 2026
The incident has raised concerns among other franchises that may have been affected by the same breach.
organisation Media/Press
‎Wednesday, August 26, 2026 3:58:33 PM
Threat actors used a previously unknown vulnerability in Interim HealthCare's database management system to target multiple entities on Sunday, August 16.
target_region United States
target_region Canada
organisation US & Canada
‎August 26, 2026
Threat actors used phishing to target Interim HealthCare entities.
organisation DataBreaches
organisation MDN
organisation Signal
‎August 28, 2026
Threat actors used phishing to compromise Interim HealthCare systems, allowing them to gain unauthorized access and potentially exfiltrate sensitive data.
‎2026/08/28
The incident reported on August 28, 2026, involves Meta Glasses being used to film someone.
organisation Meta Glasses
‎August 29, 2026
The incident affected approximately 2,071 individuals.
organisation Interim HealthCare
organisation BA
organisation HHS
organisation Amarillo
organisation CE
‎2026/08/29
The incident has raised concerns about potential targeted attacks on Interim HealthCare entities.
‎2026/08/29
Two different groups have recently attacked Interim HealthCare entities.
threat_actor ShinyHunters
organisation Click2Mail
data_breach 13,000 ombudsman complaints
financial $128 Stolen / Extorted Funds
threat_actor TeamPCP
organisation Interim HealthCare
organisation Anubis
organisation Directory of Folders
organisation Interim Healthcare Headquarters
organisation South Plains Rural Health Services
organisation SPRHS
organisation ATF
organisation DHS
financial $16.68 Settlement
organisation RSS
organisation The Doctor Alliance
organisation DataBreaches inNovember 2025
data_breach 2025 inNovember
organisation California Legislature Advances
organisation Apple’s Next AirPods May Have Cameras
organisation the Privacy Implications
organisation InterLock
organisation the Privacy Implications *
Tactical Metrics
Metrics
financial
128,000
Stolen / Extorted Funds
Metrics
data_breach
13,000
Ombudsman Complaints
Metrics
financial
16,680,000,000
Settlement
Metrics
data_breach
2,025
Innovember
Metrics
data_breach
1
Tb
Metrics
data_breach
530
Gb
Metrics
data_breach
335,093
Files
Metrics
financial
128,540
County