Ransomware victim disclosure
← All victimsRimrock Foundation
Claimed by Incransom · listed 15 hours ago
Status timeline
- ListedOct 1, 2026
- Data leakeddate unknown
At a glance
- Group
- Incransom
- Status
- Data leaked
- Country
- United States
- Listed on leak site
- Oct 1, 2026
About the victim
AI dossier — public-source company profileRimrock Foundation is a regional addiction treatment center offering comprehensive services for adults with substance use disorders and co-occurring mental health conditions. Their services include inpatient and outpatient programs, counseling, and specialized therapies.
- Industry
- Substance Abuse Treatment & Mental Health Services
Attack summary
Severity: critical — Healthcare organization handling substance abuse treatment records; patient data constitutes regulated Protected Health Information (PHI) under HIPAA, representing sensitive PII at scale.The incransom group claims to have attacked Rimrock Foundation and published data. The specific data categories exfiltrated and operational details are not stated in the available leak post excerpt.
Data the group says was taken
AI dossier — extracted from the leak post- Patient records
- Treatment history
- Personal health information
- Financial records
What the group claims
Rimrock is the largest drug and alcohol addiction treatment center in the region, offering a comprehensive range of services for adults dealing with substance use and co-occurring disorders. The organization approaches addiction as a holistic illness that affects an individual's emotional, physical, spiritual, and social well-being. Their innovative and compassionate care includes various treatment options such as inpatient and outpatient programs, counseling services, and specialized therapies. Rimrock aims to create opportunities for recovery and balance in the lives of those impacted by addiction and mental illness.
Sources
Source
Indexed 15 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

