Ransomware Group Claims Attack on Interim HealthCare

A ransomware group calling itself Anubis claims to have obtained data from Interim HealthCare, according to a listing posted to the group’s leak site on August 15, 2026. This claim was identified and is tracked by ransomware.live, a security research platform that monitors ransomware groups’ public leak sites. At this time, the claim is unverified: Interim HealthCare has not issued any public confirmation, and no regulator has confirmed that an incident occurred.

What we know — and don’t
  • A group calling itself Anubis listed Interim HealthCare on its extortion site, with a claimed date of August 15, 2026.
  • Interim HealthCare operates in the healthcare sector, which often involves sensitive patient and employee information, though this does not confirm what, if anything, was actually accessed.
  • The specific data types the group claims to have obtained have not been disclosed by the group and have not been confirmed by the company or any independent party.
  • No official statement from Interim HealthCare or a regulatory body has been made public regarding this claim as of this writing.
  • Claims made on ransomware leak sites are statements by the attackers themselves and are not independently verified at the time of posting.
What should you do if you have an account with this company?
  • Change your password for any account associated with Interim HealthCare, and avoid reusing that password on other sites.
  • Enable two-factor authentication (2FA) wherever it is offered, particularly for email, financial, and healthcare-related accounts.
  • Be cautious of unexpected emails, texts, or calls referencing this company, especially those asking you to click links, verify information, or provide payment details — these could be phishing attempts that follow reports of an alleged breach.
  • Review recent account activity and billing statements for anything unfamiliar, and report discrepancies promptly.
  • Consider using a service like Aura or LifeLock to monitor your identity and personal information for signs of misuse, particularly if you believe your data may have been involved.
  • Keep records of any suspicious communications in case they are needed later for reporting or verification purposes.

This claim has not been confirmed by Interim HealthCare or any regulatory authority. BreachLetter will update this page if the company issues a statement, if the incident is officially reported to regulators, or if further verified information becomes available.

Leave a Comment