A ransomware group calling itself IncRansom claims to have targeted an organization identified as ‘Wellness Partners network (combined revenue)’, with the claim dated September 7, 2026. This claim was not made in a court filing, a regulatory disclosure, or a statement from the company — it appears on the group’s own dark web leak site, a listing tracked and archived by ransomware.live, a security research platform that monitors ransomware groups’ public extortion pages. At this stage, this is solely an unverified claim made by a criminal group as part of its extortion tactics, and it should be treated as such until independently confirmed.
What we know — and don’t
- IncRansom listed a claimed attack date of September 7, 2026, on its leak site.
- The named entity, described as ‘Wellness Partners network (combined revenue)’, appears to operate in the healthcare/wellness space, though its full corporate structure is not confirmed here.
- The specific types of data allegedly accessed — such as patient records, financial details, or employee information — have not been disclosed by the group or confirmed by any independent party.
- No regulator, breach-notification filing, or statement from the company has confirmed this incident as of this writing.
- The listing was identified through ransomware.live, which aggregates and tracks claims posted to ransomware groups’ own extortion sites; inclusion in that tracker does not itself verify the underlying claim.
What should you do if you have an account with this company?
- Change your password for any account associated with this company, and avoid reusing that password elsewhere.
- Enable two-factor authentication (2FA) wherever it is offered, ideally using an authenticator app rather than SMS.
- Be cautious of unexpected emails, texts, or calls referencing this company, especially those asking you to click links, verify account details, or make payments — these could be phishing attempts exploiting the situation.
- Review recent account activity and billing statements for anything unfamiliar.
- Consider signing up for identity monitoring so you’re alerted quickly if your personal information turns up somewhere it shouldn’t — services like a service like Aura or LifeLock can help flag misuse early.
- Keep an eye on official communications from the company itself, and be skeptical of unofficial sources claiming to have inside information.
BreachLetter will update this article if Wellness Partners network confirms this incident, if it is reported to regulators, or if further verified details emerge.