GENESIS and Anubis Ransomware Gangs Target Interim HealthCare

Two Ransomware Gangs, GENESIS and Anubis, Claim Breach of Interim HealthCare

HIGH
September 11, 2026
4m read
RansomwareData BreachThreat Actor

Impact Scope

Affected Companies

Interim HealthCare

Industries Affected

Healthcare

Geographic Impact

United States (national)

Related Entities

Threat Actors

GENESISAnubis

Other

Anubis Ransomware Interim HealthCare

Full Report

Executive Summary

Interim HealthCare, a leading U.S. provider of home care and healthcare staffing services, is the apparent victim of a complex cyberattack involving two distinct ransomware gangs. In August 2026, both the GENESIS and Anubis ransomware groups posted claims on their respective dark web leak sites, asserting they had independently breached the company's network. The groups claim to have exfiltrated a combined total of over 1.5 terabytes of sensitive data, including patient medical records and corporate financial information. This double-claim scenario complicates the incident response and highlights the severe data security risks facing the healthcare sector.

Threat Overview

The competing extortion claims appeared just days apart, suggesting either a sequential compromise or two independent intrusions.

  • GENESIS Claim (August 10, 2026): The GENESIS group was the first to list Interim HealthCare, claiming to have stolen approximately 1 terabyte of data. Their post suggested the attack targeted the provider's locations in Oklahoma City and Tulsa, with the stolen data including patient medical records and clinical information.

  • Anubis Claim (August 21, 2026): Eleven days later, the Anubis ransomware group made its own claim. Anubis alleged it had exfiltrated 530 gigabytes of corporate data, such as franchisee financial details, internal audits, and business communications. The group has reportedly published samples of the stolen data, indicating a ransom was likely not paid.

Interim HealthCare has not officially confirmed the breaches. However, a related entity in Oklahoma reported a hacking incident to the U.S. Department of Health and Human Services (HHS) on July 31, 2026, which may be connected.

Technical Analysis

Both groups employ a double extortion strategy, which involves:

  1. T1048 - Exfiltration Over Alternative Protocol: Stealing sensitive data from the victim's network before encryption.
  2. T1486 - Data Encrypted for Impact: Encrypting files on the victim's systems to cause operational disruption.
  3. Extortion: Threatening to publish the stolen data on a public leak site if the ransom is not paid.

The Anubis Ransomware is noted to be particularly destructive, as it reportedly includes an optional "wipe mode" that can permanently destroy files, even if a ransom is paid or backups are available.

Impact Assessment

The alleged breach poses a severe threat to Interim HealthCare and its patients.

  • Patient Data Exposure: The theft of protected health information (PHI) could lead to identity theft, fraud, and a significant violation of patient privacy, with major implications under HIPAA.
  • Operational Disruption: If systems were encrypted, it could severely impact the delivery of care to patients relying on home health and hospice services.
  • Financial and Reputational Damage: The incident could result in substantial regulatory fines, legal costs from class-action lawsuits, and a loss of trust from patients and business partners.
  • Complex Incident Response: Dealing with two separate threat actors with competing claims creates a highly complex negotiation and remediation scenario.

IOCs — Directly from Articles

No specific Indicators of Compromise were provided in the source articles.

Cyber Observables — Hunting Hints

Security teams can hunt for signs of Anubis or similar ransomware activity:

Type
Network Traffic Pattern
Value
Large, anomalous data uploads to unknown destinations
Description
A key indicator of data exfiltration preceding encryption. Monitor for unusual traffic from file servers or databases.
Type
File Name
Value
Ransom notes appearing on multiple systems
Description
The presence of ransom notes is a clear sign of a ransomware attack.
Type
Process Name
Value
wiper.exe or similar
Description
The Anubis ransomware is known to have a file-wiping component; look for processes performing rapid file deletion or overwriting.

Detection & Response

  1. EDR/XDR: Deploy endpoint detection and response tools configured to detect ransomware behaviors, such as rapid file encryption, shadow copy deletion (vssadmin), and the creation of ransom notes.
  2. Data Loss Prevention (DLP): Use network and endpoint DLP solutions to monitor and alert on large-scale exfiltration of sensitive data, especially PHI.
  3. Threat Hunting: Proactively hunt for signs of lateral movement using tools like RDP or PsExec, which are common precursors to ransomware deployment.

Key D3FEND techniques include D3-NTA: Network Traffic Analysis for exfiltration detection and D3-FR: File Restoration as a core response capability.

Mitigation

Standard ransomware defenses are critical for healthcare organizations:

  1. Offline Backups: Maintain immutable, offline backups of critical data and systems and regularly test the restoration process.
  2. Network Segmentation: Segment networks to prevent ransomware from spreading from IT systems to critical clinical systems or between different business units.
  3. Multi-Factor Authentication (MFA): Enforce MFA on all remote access points (VPNs, RDP) and for all privileged accounts.
  4. User Training: Conduct regular phishing awareness training for all employees, as it remains a primary initial access vector for ransomware.

Timeline of Events

1
July 31, 2026
An Oklahoma City entity related to Interim HealthCare reports a hacking incident to HHS.
2
August 10, 2026
The GENESIS ransomware group lists Interim HealthCare on its data leak site.
3
August 21, 2026
The Anubis ransomware group posts its own claim of breaching Interim HealthCare.
4
September 11, 2026
This article was published

MITRE ATT&CK Mitigations

Deploy and maintain EDR solutions that use behavioral analysis to detect and block ransomware activity.

Mapped D3FEND Techniques:

Segment the network to isolate critical patient data and clinical systems from general IT networks to contain the spread of ransomware.

Mapped D3FEND Techniques:

Enforce MFA on all remote access points and privileged accounts to prevent credential abuse, a common ransomware precursor.

Mapped D3FEND Techniques:

Timeline of Events

1
July 31, 2026

An Oklahoma City entity related to Interim HealthCare reports a hacking incident to HHS.

2
August 10, 2026

The GENESIS ransomware group lists Interim HealthCare on its data leak site.

3
August 21, 2026

The Anubis ransomware group posts its own claim of breaching Interim HealthCare.

Sources & References

Two Ransomware Gangs Claim Interim HealthCare Hack
Shattered (shattered.io) September 10, 2026
Two Ransomware Groups Claim Attacks on Nationwide Home Healthcare Provider
HIPAA Journal (hipaajournal.com) September 9, 2026

Article Author

Jason Gomes

Jason Gomes

• Cybersecurity Practitioner

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.

Threat Intelligence & AnalysisSecurity Orchestration (SOAR/XSOAR)Incident Response & Digital ForensicsSecurity Operations Center (SOC)SIEM & Security AnalyticsCyber Fusion & Threat SharingSecurity Automation & IntegrationManaged Detection & Response (MDR)

Editorial Standards & Analyst Review

CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.

Tags

RansomwareData BreachHealthcareAnubisGENESISDouble ExtortionHIPAA

📢 Share This Article

Help others stay informed about cybersecurity threats

🎯 MITRE ATT&CK Mapped

Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.

🧠 Enriched & Analyzed

Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.

🛡️ Actionable Guidance

Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.

🔗 STIX Visualizer

Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.

Sigma Generator

Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.