Ransomware victim disclosure
← All victimsRiviera Healthcare Center
Claimed by Interlock · listed 5 hours ago
Status timeline
- ListedOct 7, 2026
- Data leakeddate unknown
At a glance
- Group
- Interlock
- Status
- Data leaked
- Country
- United States
- Sector
- Healthcare
- Listed on leak site
- Oct 7, 2026
About the victim
AI dossier — public-source company profileRiviera Healthcare Center is a for-profit skilled nursing facility that has operated for over 50 years, providing 24-hour nursing and rehabilitation services to patients requiring post-acute care.
- Industry
- Skilled Nursing Facilities & Rehabilitation Services
- Founded
- 1974
Attack summary
Severity: critical — Confirmed exfiltration of regulated protected health information (PHI) at scale in a healthcare setting, subject to HIPAA compliance requirements. Exposure includes sensitive medical records, diagnoses, and financial/payment data affecting multiple patients and staff.The group claims to have exfiltrated patient protected health information (PHI) including names, diagnoses, medical histories, fall/fracture and treatment information, payment records, and employee/HR data from the facility due to poor security practices.
Data the group says was taken
AI dossier — extracted from the leak post- Patient names
- Medical diagnoses
- Medical histories
- Fall and fracture records
- Treatment information
- Payment records
- Employee/HR data
What the group claims
Riviera Healthcare Center is a for-profit skilled nursing facility in operation for over 50 years. It provides 24-hour nursing and rehabilitation services. Due to negligence and poor security practices, confidential data was exposed, including patient protected health information (PHI)names, diagnoses, medical histories, fall/fracture and treatment information, payment records, and employee/HR data. This breach violates HIPAA and the California CMIA (and potentially the CCPA/CPRA) and will result in mandatory breach notification, federal and state fines, civil lawsuits, corrective action plans, and significant reputational and financial damage.
Sources
Source
Indexed 5 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

