Interim HealthCare, a leading U.S. provider of home care and healthcare staffing services, is the apparent victim of a complex cyberattack involving two distinct ransomware gangs. In August 2026, both the GENESIS and Anubis ransomware groups posted claims on their respective dark web leak sites, asserting they had independently breached the company's network. The groups claim to have exfiltrated a combined total of over 1.5 terabytes of sensitive data, including patient medical records and corporate financial information. This double-claim scenario complicates the incident response and highlights the severe data security risks facing the healthcare sector.
The competing extortion claims appeared just days apart, suggesting either a sequential compromise or two independent intrusions.
GENESIS Claim (August 10, 2026): The GENESIS group was the first to list Interim HealthCare, claiming to have stolen approximately 1 terabyte of data. Their post suggested the attack targeted the provider's locations in Oklahoma City and Tulsa, with the stolen data including patient medical records and clinical information.
Anubis Claim (August 21, 2026): Eleven days later, the Anubis ransomware group made its own claim. Anubis alleged it had exfiltrated 530 gigabytes of corporate data, such as franchisee financial details, internal audits, and business communications. The group has reportedly published samples of the stolen data, indicating a ransom was likely not paid.
Interim HealthCare has not officially confirmed the breaches. However, a related entity in Oklahoma reported a hacking incident to the U.S. Department of Health and Human Services (HHS) on July 31, 2026, which may be connected.
Both groups employ a double extortion strategy, which involves:
T1048 - Exfiltration Over Alternative Protocol: Stealing sensitive data from the victim's network before encryption.T1486 - Data Encrypted for Impact: Encrypting files on the victim's systems to cause operational disruption.The Anubis Ransomware is noted to be particularly destructive, as it reportedly includes an optional "wipe mode" that can permanently destroy files, even if a ransom is paid or backups are available.
The alleged breach poses a severe threat to Interim HealthCare and its patients.
No specific Indicators of Compromise were provided in the source articles.
Security teams can hunt for signs of Anubis or similar ransomware activity:
wiper.exe or similarvssadmin), and the creation of ransom notes.Key D3FEND techniques include D3-NTA: Network Traffic Analysis for exfiltration detection and D3-FR: File Restoration as a core response capability.
Standard ransomware defenses are critical for healthcare organizations:
Deploy and maintain EDR solutions that use behavioral analysis to detect and block ransomware activity.
Mapped D3FEND Techniques:
Segment the network to isolate critical patient data and clinical systems from general IT networks to contain the spread of ransomware.
Mapped D3FEND Techniques:
Enforce MFA on all remote access points and privileged accounts to prevent credential abuse, a common ransomware precursor.
Mapped D3FEND Techniques:
An Oklahoma City entity related to Interim HealthCare reports a hacking incident to HHS.
The GENESIS ransomware group lists Interim HealthCare on its data leak site.
The Anubis ransomware group posts its own claim of breaching Interim HealthCare.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.