BRIEFRansomwarehighP48
Incransom ransomware lists addiction center Rimrock Foundation
Rimrock Foundation
Detected1 October 2026 · 13:36 UTC
The incransom ransomware group has listed Rimrock Foundation, a large US addiction-treatment provider, on its leak site. Healthcare victims face operational disruption and exposure of highly sensitive patient records. It signals active targeting of the healthcare sector, so defenders should watch for related extortion activity.
CategoryRansomware
Severityhigh
Priority score48
Detected1 October 2026 · 13:36 UTC
Ransomware● 48
Ransomware Chaos publica a la clínica dental Park DentalThe chaos ransomware group published Park Dental, a UK dental clinic, threatening to release stolen data if management does not respond within 24 hours. Healthcare providers hold sensitive patient records that make them high-value extortion targets. This is a live, time-sensitive extortion case worth monitoring for data release.Ransomware● 60
Ransomware n0n publica a la clínica Houston Thyroid & EndocrineRansomware group n0n published Houston Thyroid & Endocrine Specialists, listing 14,441 patient document scans with lab results, diagnoses, insurance and billing data, plus SSNs and dates of birth. The leak exposes protected health information of thousands and fuels downstream medical-identity fraud. A deadline of 2026-10-04 marks an active, time-sensitive extortion.Ransomware● 50
Ransomware kairos publica al centro hospitalario francés CNEHThe ransomware group kairos published Le Centre National de l'Expertise Hospitalière (CNEH), a French healthcare training organization, as a new victim on its leak site. Healthcare ransomware disrupts patient-facing services and exposes sensitive data. Health-sector defenders should verify exposure and prepare for leaked records and extortion pressure.Ransomware● 36
Ransomware safepay publica a la belga Assist2EnjoySafepay listed Belgian appliance retailer Assist2Enjoy, a small wholesale/retail firm established in 2015. Impact is low, but it is a freshly published victim that shows the group's active campaign. Relevant mainly as a signal of ongoing ransomware activity in Europe.Ransomware● 44
Ransomware safepay publica a la alemana econ-tecThe safepay ransomware group published German industrial-engineering firm econ-tec, exposing design, automation and process-optimization project data. Industrial firms feed supply chains, so leaked schematics and client data can enable further downstream attacks. Outside Latin America but relevant to industrial-sector defenders.Ransomware● 62
Ransomware emperador publica a SitePro RentalsRansomware group emperador published SitePro Rentals as a victim, threatening to leak active employee details within 72 hours if not contacted. A referenced class-action filing dated 28 September 2026 confirms the incident is current. Leaked employee and departmental data can fuel phishing and insider targeting, so the victim's clients and partners should be alert.