Ransomware Group ‘Genesis’ Claims Attack on Interim HealthCare (Oklahoma and Tulsa)

A ransomware group calling itself Genesis claims to have carried out an attack against Interim HealthCare (Oklahoma and Tulsa), with the claim dated August 10, 2026. This claim was posted on the group’s own dark-web leak site and has been tracked by ransomware.live, a security research platform that monitors ransomware groups’ public leak sites. At this time, the claim has not been independently verified, and it should be treated as an unconfirmed statement from a criminal group rather than an established fact.

What we know — and don’t
  • A group identifying itself as Genesis listed Interim HealthCare (Oklahoma and Tulsa) on its leak site with a claimed date of August 10, 2026.
  • Interim HealthCare operates in the healthcare sector, which often involves sensitive patient and employee information, though this does not confirm what, if any, data was actually involved in this specific claim.
  • The specific types of data the group claims to have obtained have not been disclosed or confirmed by any party.
  • Interim HealthCare has not issued a public statement confirming or denying the incident as of this writing.
  • No regulatory filing or breach notification tied to this claim has been identified at this time.
What should you do if you have an account with this company?
  • Change your password for any account associated with Interim HealthCare, and avoid reusing that password on other sites.
  • Enable two-factor authentication (2FA) wherever it is offered, particularly for email, financial, and healthcare portal accounts.
  • Be cautious of unexpected emails, texts, or calls referencing Interim HealthCare, especially those urging urgent action or requesting personal information — these could be phishing attempts capitalizing on this claim.
  • Monitor your financial and insurance statements for unfamiliar activity, and consider placing a fraud alert or credit freeze if you notice anything suspicious.
  • Since healthcare-related claims can sometimes involve personal identifiers, using a service like a service like Aura or LifeLock to watch for signs of identity misuse can add an extra layer of protection while this situation remains unconfirmed.

BreachLetter will update this page if Interim HealthCare (Oklahoma and Tulsa) confirms this incident, issues a public statement, or if the matter is officially reported to regulators.

Leave a Comment