Ransomware Group Claims Attack on Integrated Health Systems

A ransomware group calling itself coinbasecartel claims to have carried out an attack on Integrated Health Systems, with the claim dated August 22, 2026. This claim originates from the group’s own leak-site listing, which is tracked and cataloged by ransomware.live, a security research platform that monitors public statements made by ransomware groups. At this time, the claim has not been independently verified, and Integrated Health Systems has not issued any public confirmation of an incident.

What we know — and don’t
  • A group identifying itself as coinbasecartel posted a claim referencing Integrated Health Systems on its leak site, dated August 22, 2026.
  • Integrated Health Systems operates in the healthcare sector, though the group’s claim itself does not describe the company’s operations in detail.
  • The specific types of data the group claims to have obtained — such as patient records, financial information, or employee data — have not been disclosed or confirmed in any verified source.
  • No regulator, breach notification body, or the company itself has confirmed that an incident occurred.
  • As with all ransomware group claims, the possibility of exaggeration, fabrication, or misattribution cannot be ruled out until independently verified.
What should you do if you have an account with this company?
  • Change your password for any account associated with Integrated Health Systems, and avoid reusing that password on other sites.
  • Enable two-factor authentication (2FA) wherever it is offered, particularly for accounts tied to health or financial information.
  • Be alert to phishing emails, texts, or phone calls that reference this company or claim to be following up on a security incident — attackers often use claims like this one to craft convincing lures.
  • Monitor bank and insurance statements for unfamiliar activity, especially if the company handles billing or payment information.
  • Consider using an identity monitoring service like a service like Aura or LifeLock to get alerted if your personal information appears in places it shouldn’t.
  • Keep records of any suspicious communications in case they are needed later for reporting or documentation purposes.

BreachLetter will update this page if Integrated Health Systems confirms this incident, issues a public statement, or if the matter is officially reported to regulators.

Leave a Comment