Two separate ransomware gangs have posted claims against Interim HealthCare, a home healthcare provider that operates across 40 U.S. states, according to The HIPAA Journal. The group known as GENESIS listed the company on its dark-web leak site on August 10, 2026, claiming to have stolen roughly 1 terabyte of data. Eleven days later, on August 21, a second group calling itself Anubis added Interim HealthCare to its own extortion portal, claiming a separate haul of 530 gigabytes.

Neither claim has been independently verified. Interim HealthCare has not confirmed a breach in any statement found in current reporting, and no filing tied specifically to either group’s allegations had appeared on the U.S. Department of Health and Human Services’ Office for Civil Rights breach portal as of this writing. What is confirmed is narrower but still notable: both postings exist, they name the same corporate target within an 11-day window, and threat-intelligence researchers, including the blog SecurityArsenal, tracked the activity within days of it appearing.

Two Ransomware Groups, One Home Healthcare Target

Interim HealthCare runs on a franchise model, delivering home health, hospice and staffing services through locally operated offices under one national brand. A related entity, Interim HealthCare of Oklahoma City Inc., has separately appeared in breach-notification tracking tied to the same corporate family, per HIPAA Journal reporting, though it is not clear from available sources whether that filing connects to either ransomware group’s current claim or to an unrelated incident.

That franchise structure matters here. It means a single leak-site listing under the Interim HealthCare name could plausibly refer to one local office, a regional operator, or the corporate parent, and public reporting so far has not resolved which. Home healthcare agencies handle patient scheduling, clinical notes and caregiver payroll across dozens of semi-independent locations, which is exactly the kind of distributed environment ransomware crews have learned to target.

Timeline: How the Claims Surfaced in August 2026

  • August 10, 2026: GENESIS posts a listing for Interim HealthCare on its dark-web leak site, claiming roughly 1 TB of exfiltrated data, per HIPAA Journal.
  • August 10-11, 2026: SecurityArsenal’s monitoring records GENESIS posting four new victims in a 48-hour window, three of them U.S. healthcare organizations, including two separate postings referencing Interim HealthCare entities.
  • August 12, 2026: SecurityArsenal publishes an analysis flagging the cluster of healthcare victims as a sign of active targeting of the sector.
  • August 21, 2026: Anubis lists Interim HealthCare on its own extortion site, claiming approximately 530 GB of data centered on financial and franchise records.
  • September 2026: The dual claims circulate across breach-tracking sites such as Ransomware.live, but Interim HealthCare has issued no public confirmation or denial found in current reporting.

What’s Confirmed and What’s Still Just a Claim

It helps to separate two different questions that get blurred together in ransomware coverage. The first is whether a criminal group posted a threat. The second is whether that threat reflects a real, successful breach with real stolen files. The first question is settled here: both postings are real and dated, and multiple outlets tracking dark-web activity logged them independently. The second question is not settled, and treating a leak-site claim as proof of a breach is a common mistake that ransomware crews rely on.

Ransomware gangs have financial incentive to exaggerate. A bigger claimed haul creates more leverage during extortion negotiations, whether or not the underlying data matches the description. Some leak-site postings later turn out to reference recycled data from earlier breaches, data pulled from a single compromised vendor rather than the named company directly, or in rare cases fabricated listings meant purely to extract a payment before any real intrusion occurred. None of that means the Interim HealthCare claims are false. It means they remain unverified pending either a company statement, a regulatory filing, or independent forensic review.

Inside the GENESIS Posting: 1 TB and an Oklahoma City Filing

GENESIS’s August 10 listing describes the stolen material as covering medical records, healthcare data, personal data, patient lists, clinical data and general company data, according to HIPAA Journal’s review of the posting. The group threatened to publish the files if a ransom was not paid, a standard double-extortion tactic in which stolen data functions as leverage independent of whether systems get encrypted.

The GENESIS listing did not stand alone. SecurityArsenal’s tracking shows the group posted four victims in a single 48-hour window around that date, and three were U.S. healthcare organizations, two of them carrying the Interim HealthCare name. The firm reads that pattern as consistent with either a franchise-wide compromise touching more than one local office, or a deliberate pressure tactic designed to make a single intrusion look larger by splitting it across multiple postings. Public reporting has not determined which explanation is correct.

Inside the Anubis Posting: 530 GB of Franchise Records

Anubis’s August 21 listing describes a smaller volume, about 530 GB, and a different flavor of data. In the wording of the leak-site posting itself, as reviewed in HIPAA Journal’s coverage, the group described the material as covering “financial information about franchisees, details of internal and external audits, discussions of operational issues, as well as memoranda covering all kinds of day-to-day business matters.”

That description leans toward corporate and franchise business records rather than clinical patient files, which is a meaningful distinction if it holds up. A breach centered on franchisee finances and internal memos carries different regulatory exposure than one centered on protected health information, even though both would be damaging to a healthcare brand’s reputation. It is also possible the full dataset includes patient data that simply was not highlighted in the group’s own summary, since leak-site descriptions are marketing copy written by the attacker, not an audited inventory.

GENESIS vs. Anubis: Comparing the Two Claims

DetailGENESISAnubis
Date postedAugust 10, 2026August 21, 2026
Claimed data volume~1 TB~530 GB
Data types claimedMedical records, clinical data, patient lists, personal data, company dataFranchisee financials, audit records, internal memos, operational documents
Group first observedBy at least March 2026 (leak site active)Late 2024 emergence; public launch February 2025
Business modelNot clearly documented publiclyRansomware-as-a-service, double extortion, optional wiper mode
Ransom amount disclosedNot disclosed in public postingsNot disclosed in public postings
Independent verificationUnconfirmedUnconfirmed

Who Is Anubis? A Well-Documented Double-Extortion Operation

Of the two groups, Anubis has the longer public track record. It emerged in late 2024 as a rebrand of an earlier operation called Sphinx and announced itself on the underground forum RAMP in February 2025, according to The Hacker News. It runs as a ransomware-as-a-service operation, meaning affiliates rent its tools and infrastructure in exchange for a cut of any ransom collected, and it favors the now-standard double-extortion playbook: steal data first, encrypt second, then threaten to publish the files.

Anubis also carries an unusual feature for a ransomware strain: an optional wipe mode that destroys files outright rather than only encrypting them, which researchers at ProvenData have documented as part of its technical profile. Victim-tracking services put its total public claims at roughly 107 to 108 named organizations as of early September 2026, with healthcare representing about 26% of its known victims by sector, the largest single category ProvenData tracks for the group. Past listings attributed to Anubis include the Adriatic Port Authority in Italy, the Hawaii law firm Lung Rose Voss Wagnild, the supermarket chain Winn-Dixie, and Fairlife, a Coca-Cola-owned brand that the company itself publicly confirmed was affected.

Who Is GENESIS? A Newer, Thinly Documented Player

GENESIS is a different story. Open-source threat research on the group is sparse compared with Anubis, and most of what is public comes from incident-by-incident write-ups rather than a full technical profile. Its leak site appears to have been operating by at least March 2026, when it listed the city government of Hart, Michigan, according to Comparitech. Through mid-2026 it added construction firms, including Building Envelope Systems and C.A. Walker Construction, before the burst of healthcare-focused postings in August that included the Interim HealthCare listings, per SecurityArsenal’s tracking.

No public source reviewed for this story offers a confirmed classification of GENESIS as a ransomware-as-a-service brand, a closed operator, or an affiliate of an existing crew operating under a new name, which is itself common in this space. Groups rebrand constantly to shake off law enforcement attention and sanctions lists, and a leak site with a short public history does not necessarily mean the operators are new to the business.

Why the Same Victim, Twice, Isn’t That Unusual

Two different gangs claiming the same company within a couple weeks reads like a coincidence, but it happens often enough in this ecosystem to have a few standard explanations. Access brokers sell stolen credentials or network footholds to multiple buyers. Two affiliates working from the same ransomware-as-a-service platform, or from two different platforms, sometimes breach different parts of a sprawling, multi-location organization independently. And because franchise businesses run semi-autonomous local IT environments, it is entirely possible GENESIS and Anubis each compromised a different Interim HealthCare location, or a different vendor connected to it, without either group touching the other’s intrusion at all.

The differing data descriptions support that read. GENESIS describes clinical and patient-facing records. Anubis describes franchise financial and audit material. Those look less like two groups fighting over the same stolen archive and more like two separate incidents, or two separate slices of a larger, decentralized environment. Without a forensic statement from Interim HealthCare, that remains an educated read of public evidence rather than a settled fact.

Home Healthcare’s Widening Attack Surface

Franchise-model healthcare businesses carry a specific set of weaknesses that ransomware operators have learned to exploit. Individual locations often run their own workstations, local networks and sometimes their own cloud accounts, tied back to shared corporate systems for scheduling, payroll and electronic health records. That setup produces uneven patching, inconsistent security tooling from one office to the next, and multiple paths into the same corporate backbone.

Credential exposure compounds the problem. Breach-tracking firm BreachSense has found that roughly 32% of organizations later listed as Anubis victims had employee credentials leaked somewhere online in the 12 months before the attack, a pattern consistent with how initial access brokers scout targets across the ransomware ecosystem generally. In a franchise setting, a single leaked password from one location’s remote-access tool or shared SaaS login can potentially open a path into other locations or into central systems, since decentralized businesses frequently lean on the same handful of vendors for scheduling, payroll and clinical documentation across every office.

The 2026 Healthcare Breach Numbers So Far

Whatever the outcome of these two specific claims, they land in a sector already absorbing a heavy breach-reporting load in 2026. Different trackers slice the numbers differently depending on cutoff dates and filters, but every count points the same direction: a large, steady stream of large healthcare breaches reported to the HHS Office for Civil Rights this year.

Period (2026)Reported BreachesIndividuals AffectedSource
January461,441,182HIPAA Journal
March668.7 million+HIPAA Journal
Jan. 1 – Apr. 30252Not separately broken outHIPAA Journal
H1 (through June 5)28320.5 millionMedcurity, via HHS OCR data
H1 (through June 30)18919 million+Paubox / HealthTechSecurity, via HHS OCR
Cumulative since Oct. 20097,419935 million+HIPAA Journal, as of Sept. 3, 2026

The gap between the 189, 252 and 283 figures for overlapping 2026 periods comes down to methodology, cutoff dates and whether a tracker uses the finalized OCR portal view or the under-investigation view. Medcurity’s analysis of the H1 figures found that 87% of breaches in its count, 246 of 283, were categorized as hacking or IT incidents rather than lost devices, insider error or other causes, which is the bucket ransomware and data-theft extortion fall into.

Market and Regulatory Fallout to Watch

If either claim is confirmed, federal rules give Interim HealthCare a 60-day window from discovery to notify affected individuals and file with HHS OCR once a breach involving protected health information is established. A multi-state franchise footprint also raises the possibility of state attorney general notifications layered on top of the federal requirement, since several states carry their own breach-notification deadlines shorter than 60 days.

The broader ransomware economy gives useful context for how seriously to weigh these threats. Chainalysis’s 2026 Crypto Crime Report found that total on-chain ransomware payments actually fell about 8%, to $820 million, in 2025, even as the number of claimed attacks rose roughly 50% year over year. Read together, that suggests more groups are posting more claims while victims pay out less often or negotiate down harder, a dynamic that raises the incentive for gangs to inflate claimed data volumes to keep leverage in negotiations. For a franchise brand, even an unconfirmed claim can dent trust among prospective franchisees, referral partners and cyber insurers well before any forensic finding is public.

Five Predictions for What Happens Next

  • A company statement becomes likely within weeks. Once a listing generates trade-press coverage, targeted companies typically issue at least a short acknowledgment or denial, especially if either group publishes sample files to prove its claim.
  • More postings may surface under related entity names. Given the franchise structure, additional local Interim HealthCare offices could appear on either leak site, or on a third group’s site, if the underlying access point remains open.
  • An HHS OCR filing is the marker to watch. A new entry naming Interim HealthCare on the breach portal would be the first hard confirmation independent of the attackers’ own claims.
  • GENESIS will likely get a fuller threat profile soon. Anubis went from an obscure rebrand to a well-documented operation within roughly a year of its 2025 launch; GENESIS appears to be on a similar trajectory as more researchers start tracking it.
  • Expect renewed scrutiny of franchise-model healthcare IT. Insurers, regulators and industry groups tend to react to high-profile decentralized-business breaches by pushing for standardized security baselines across franchise networks, not just at the corporate level.

What Home Healthcare Providers and Patients Should Do Now

For patients and families connected to Interim HealthCare, the practical advice does not change much whether or not the claims are eventually confirmed. Watch for official communication directly from the company rather than third parties, be skeptical of unsolicited calls or emails referencing the incident since scammers routinely exploit breach headlines to run phishing campaigns, and consider placing a free credit freeze if any notification letter does arrive. Reports of breach-related scams can be filed with the FBI’s Internet Crime Complaint Center.

For the broader home healthcare and franchise-staffing industry, the immediate lesson is less about this specific pair of claims and more about the structural exposure they highlight. Franchise agreements can mandate minimum security baselines the same way they mandate branding and service standards, vendor risk assessments should extend down to individual franchise locations rather than stopping at the corporate contract level, and credential-monitoring services can catch leaked employee logins before they turn into the kind of initial access researchers have tied to a third of known Anubis victims.

Frequently Asked Questions

Has Interim HealthCare confirmed it was hacked?

No. As of this writing, Interim HealthCare has not issued a public statement confirming a breach tied to either the GENESIS or Anubis claims, and no filing matching these specific incidents had appeared on the HHS Office for Civil Rights breach portal.

What is Interim HealthCare?

Interim HealthCare is a franchise-based home healthcare provider operating across 40 U.S. states, offering home health, hospice and healthcare staffing services through locally run offices.

What are GENESIS and Anubis?

Both are ransomware or data-extortion groups that operate dark-web leak sites where they list alleged victims and threaten to publish stolen data. Anubis is the better-documented of the two, operating since early 2025 as a ransomware-as-a-service brand with a double-extortion model. GENESIS is newer and far less documented, with a leak site that appears to have been active since at least March 2026.

How much data do the groups claim to have stolen?

GENESIS claims about 1 terabyte of data, including medical and clinical records. Anubis claims about 530 gigabytes, described as franchise financial, audit and internal business records. Neither figure has been independently verified.

Why would two ransomware groups claim the same company?

This can happen when stolen credentials or network access get resold to multiple criminal groups, when separate affiliates breach different parts of a large, decentralized organization independently, or when a franchise business has more than one weakly secured entry point. It is also possible one or both claims involve a different local office or vendor rather than the same intrusion.

What should Interim HealthCare patients and employees do right now?

Watch for official communication directly from the company, be cautious of unsolicited messages referencing the incident, and consider a credit freeze if a formal notification letter arrives. Suspicious calls or emails exploiting the news can be reported to the FBI’s Internet Crime Complaint Center.

How common are ransomware attacks on healthcare organizations in 2026?

Healthcare has reported a steady stream of large breaches to HHS OCR throughout 2026, with counts ranging from roughly 189 to 283 large breaches in the first half of the year depending on the tracker, affecting between 19 million and 20.5 million individuals. Most of those incidents fall into the hacking and IT-incident category that includes ransomware and data-theft extortion.

Where can I check if my data has appeared in a reported breach?

The HHS Office for Civil Rights maintains a public breach portal listing healthcare breaches affecting 500 or more individuals, and independent trackers such as Ransomware.live and DataBreaches.net monitor dark-web leak-site claims as they appear.