Interim HealthCare of Oklahoma City Inc., is currently facing a data breach that has been claimed by two separate ransomware gangs, creating confusion about how the groups operate.
What happened
On August 31st, 2026, Interim HealthCare filed a data breach notice with the Department of Health and Human Services (HHS), which was posted by the HHS soon after. According to the filing, Interim Healthcare believes at least 500 individuals were impacted, but has not specified the number of victims, likely because they are still investigating the incident. The home healthcare provider, which operates in 40 states, has not yet posted a data breach notice, but according to Beyond Machines, some personally identifiable information (PII) and protected health information (PHI) may have been involved.
Going deeper
Unique to this case is that two separate ransomware organizations claimed to have data from Interim Healthcare. First, ransomware group Genesis claims to have approximately one terabyte of data, which they claim includes medical records, healthcare data, and additional company records.
However, soon after Genesis posted that they had stolen data, another group, known as Anubis, similarly claimed to have hacked into Interim HealthCare’s system. Anubis claims to have 530 gigabytes of data, including financial information about franchises and internal business communication. Anubis has already published samples of the data, which can be previewed (without identifying information) on Ransom Look. Genesis has threatened to release data but has not provided any proof of it.
In the know
Anubis is a financially motivated group, according to Ransom Look, and is Russian-speaking. The group was first identified in 2016 and is known to target malicious email attachments or exploit unpatched vulnerabilities. The group uses Tor, an open-source anonymous network, to deliver information to victims. The group allegedly has an affiliate program, paying other criminals for assistance and to increase their ability to attack multiple organizations. It’s also possible they could run other affiliate programs, like Ransomware-as-a-Service (Raas), where smaller ransomware groups use Anubis’ software or technology and give them some of their profit if an attack is successful.
Genesis ransomware was first discovered in late 2025, but, according to Ransomware Live, may have become active in mid 2024. The group’s location is currently unknown, but they tend to attack small and mid-sized organizations in the US. The group focuses on double-extortion tactics, meaning they both steal and encrypt data so that it is inaccessible to the victimized organization. While Genesis has attacked many different types of companies, in early 2026, they claimed to have stolen 645 gigabytes of data from Stockton Cardiology, a California-based healthcare company. Stockton Cardiology did not pay a ransom, and the stolen data was ultimately published online.
The big picture
With two threat groups claiming to have attacked Interim HealthCare, it’s possible that Interim HealthCare was attacked twice, especially considering the groups claim to have different types of data. However, it’s also very possible that one of the groups is lying, and doesn’t actually have the data, or that the two groups are working together in hopes of extorting Interim twice.
It’s common for groups to be affiliated with each other, especially in RaaS situations, where one group may have received assistance from the other in exchange for some of the ransom funds. Neither ransomware group has acknowledged a potential connection.
As Interim Healthcare continues to investigate, it will likely become more clear if they experienced a second breach or if the ransomware gangs are referring to the same incident. Regardless, the multiple claims are a reminder that ransomware organizations should never be trusted, and healthcare companies should always seek advice from law enforcement before engaging in ransomware negotiations. Secondly, the potential of two breaches shows that once an organization is vulnerable to attack, it’s very easy for criminals to take advantage and potentially spread the word. Healthcare companies should constantly monitor their systems for suspicious activity or potential vulnerabilities.
FAQs
Will Interim HealthCare clarify who was responsible for the attack filed in August?
It’s unlikely Interim will specifically name an organization as responsible for the incident, but it is possible that they will file another notice. Interim will also eventually need to notify victims. In the notification, Interim will likely specify what data was accessed, which may also make it clearer who caused the breach, as the gangs claim to have different information.
Is it possible for organizations to be breached multiple times?
Yes, it’s very possible for an organization to be breached several times, especially if the victim paid a ransom, which can embolden the attackers to strike again. Since many hacks are based on opportunity, if an organization has particularly weak network protection, it’s also possible that different, unaffiliated organizations will attack.
Why hasn’t Interim HealthCare published a notice?
Data breaches can be very complex situations, especially if multiple actors are involved. In some cases, organizations delay notification if it may impede investigation. It’s likely that Interim is acting in good faith and simply wants to ensure all information is correct before it is released.
