Skip to main content

Ransomware victim disclosure

All victims

Horizon Family Medical Group

Claimed by Incransom · listed 6 hours ago

Today
Age
since listed · data leaked

Status timeline

  1. ListedJun 18, 2026
  2. Data leakeddate unknown

At a glance

Status
Data leaked
Listed on leak site
Jun 18, 2026

About the victim

AI dossier — public-source company profile

Horizon Family Medical Group is a multi-specialty medical practice offering primary care, women's health, behavioral health, allergy/immunology, ophthalmology, and nutrition services. The organization operates as a clinical group serving patients across multiple service lines.

Industry
Healthcare - Family Medicine & Multi-Specialty Clinic

Attack summary

Severity: critical — Confirmed exfiltration of regulated healthcare data at massive scale (7TB) including complete PHI (Protected Health Information) across multiple sensitive categories: psychiatric/behavioral health records, women's health, and comprehensive financial/operational data. HIPAA-regulated data with clear potential for identity theft, blackmail, and significant harm to individuals. Data reportedly already distributed and archived for permanent retention.

incransom claims to have exfiltrated the complete digital footprint of Horizon Family Medical Group, totaling 7 terabytes. The group states it has obtained patient medical records, financial databases (QuickBooks), SQL databases, and operational data, and has distributed this data for permanent archival storage.

critical

Data the group says was taken

AI dossier — extracted from the leak post
  • Complete patient medical records
  • Primary care visit histories and diagnoses
  • Prescriptions and lab results
  • Gynecological and obstetric records
  • Mental health diagnoses and psychotherapy notes
  • Psychiatric medications
  • Allergy information
  • Ophthalmology prescriptions
  • Nutrition and eating disorder records
  • QuickBooks financial databases
  • Employee salaries and executive compensation
  • Tax reports and insurance settlements
  • Doctor schedules and patient flow data
  • Revenue and profitability metrics by department

What the group claims

Horizon Family Medical Group A deep dive into 7 terabytes of internal data: from patient records to QuickBooks financial databases In the modern world, data is the new oil. For a medical organization like Horizon Family Medical Group, it is also the foundation of trust between doctor and patient. We have conducted an independent and complete audit of this organization's data security. The results are catastrophic. We are in possession of the company's entire digital footprint, totaling **7 terabytes**, which includes 1TB of file data and 6TB of mission-critical SQL and QuickBooks databases. The management of Horizon Family Medical Group was notified of their complete loss of data control. They chose silence. This blog exists to illuminate what they are desperately trying to hide. We will not be publishing the files. Yet. Instead, we will explain exactly what this data contains, so that every patient, employee, and partner can appreciate the full scale of the threat. The Patient, Dissected. What We Know About You Horizon Family Medical Group prides itself on a wide range of services, from primary care to specialized treatments. This range of services has now become a detailed vulnerability map for every single patient. Our data includes, but is not limited to: Primary Care: Complete visit histories, diagnoses, prescriptions, lab results, and physicians' private notes about your lifestyle, habits, and family status. Women's Health: Detailed information on gynecological exams, pregnancies, abortions, Pap smear results, STD diagnoses, and prescribed treatments. Everything you trusted only to your doctor. Behavioral Health: The most sensitive category. Diagnoses related to depression, anxiety disorders, bipolar disorder, and addiction. Full session notes from psychotherapists. Every antidepressant and antipsychotic prescription. This information can destroy careers, families, and social standing. Allergy and Immunology: Data on all your allergies, including reactions to specific medications. What happens when this information is lost or altered in your official medical file? Ophthalmology & Nutrition: Your eyeglass prescriptions, diagnoses like glaucoma and cataracts, as well as all your attempts to manage weight, documented eating disorders, and private recommendations from nutritionists. This isn't just 'data'. This is your life, cataloged and ready for use. Anatomy of a Business. A Financial Teardown of Horizon Family Medical Group It's a paradox that clinics, while collecting mountains of information, often fail to see the real picture of their own business. We see it. The 6 terabytes of SQL and QuickBooks databases represent the complete financial and operational model of Horizon Family Medical Group. We have analyzed: SQL Databases: These contain complete patient information, doctor schedules, office utilization, patient flow, average revenue per department and per doctor. We know which doctor is profitable and which is a liability. We see every operational metric management uses to make decisions. QuickBooks Databases: This is the financial heart of the company. Every transaction, employee salaries (including hidden executive bonuses), tax reports, debts, loans, and settlements with insurance companies and suppliers. We can see the true profit margin of every service, the customer acquisition cost (CAC), and their lifetime value (LTV). Horizon's management hasn't just lost patient data. They have lost complete control of their business. Any competitor with this information could dismantle their company by poaching their most profitable doctors and patients. Eternal Memory. Why This Data Will Never Disappear. Some believe a data breach is a temporary problem. In this case, it is not. We drew inspiration from the Arctic Code Vault project, where humanity's most critical code is preserved in permafrost for a thousand years. Your 7 terabytes of data are no longer just files on a server. They have been prepared for archival and distributed storage. They will become a digital monument to the negligence of Horizon Family Medical Group. This data cannot be 'deleted'. It will exist forever, as proof that the company's leadership failed to protect what is most sacred—your health and your privacy. To the management of Horizon Family Medical Group, we remind you: the clock is ticking. Your silence only magnifies the damage. Contact us. Your patients and your business deserve it.

Sources

Source

Indexed 6 hours ago

This page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.

Is this your supplier? Your competitor? You?

Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

Disclosure context

About Incransom

Incransom is a ransomware group that emerged in August 2023, operating with primarily financial motivations as evidenced by their targeting of high-value sectors across multiple developed nations. The group's origin and specific affiliations remain undocumented by major threat intelligence organizations, though their operational patterns suggest they likely operate independently rather than as a ransomware-as-a-service model. With 734 documented victims, Incransom has demonstrated a preference for targeting organizations in the United States, Canada, United Kingdom, Germany, and Australia, with particular focus on healthcare, technology, business services, and manufacturing sectors, though their attack methodology and specific technical capabilities have not been extensively documented by established security researchers or government agencies. The group's notable campaigns and specific high-profile victims have not been publicly detailed by CISA, FBI, Mandiant, or other reputable threat intelligence sources, suggesting either operational security effectiveness or limited visibility into their most significant operations. Based on available intelligence, Incransom appears to remain active as of recent reporting periods, though comprehensive analysis of their current operational status requires additional documentation from established threat intelligence sources. The group has been linked to 1,687 public disclosures across our corpus. First observed on a leak site on September 9, 2021; most recent post June 18, 2026. The operation is currently active.

Also tracked as: inc ransom, INC.

Timeline of this disclosure

  • June 18, 2026Horizon Family Medical Group listed by Incransomon the group's public leak site

Sector and geography

This disclosure adds to ransomware activity in the Healthcare sector, which has 2,593 disclosures indexed across all operators we track. Geographically, Horizon Family Medical Group is reported in United States, a country with 3,101 ransomware disclosures in our corpus.

If your organisation is affected

A listing by Incransom means Horizon Family Medical Group appeared on a ransomware extortion site and data attributed to it has been published. If this is your organisation, or a supplier you depend on, the priority is to confirm the intrusion and contain it before the window to act closes.

  • Engage your incident-response team and preserve forensic evidence before remediating — do not wipe affected systems first.
  • Force a password reset and revoke active sessions for exposed accounts; rotate any credentials, API keys or certificates that may have been in the stolen data.
  • Assess regulatory notification duties (GDPR, NIS2, sector regulators) — many carry a 72-hour reporting clock from awareness.
  • Report the incident to your national CERT, CISA (United States), as required for your jurisdiction.
  • Monitor for the data appearing on Incransom's leak site and across paste and breach channels, and brief downstream partners who may be exposed through you.

How we know this. Darkfield monitors public ransomware leak sites continuously, archiving every new disclosure and the data later released against the victim. Each entry on this page is sourced from the operator's own publication and cross-checked against complementary OSINT feeds (RansomLook, ransomware.live, RansomWatch). We do not collect or host stolen data — only the metadata, timestamps and screenshots needed to make the public disclosure searchable and accountable. Records here are corrected when the original post is edited, retracted, or merged with another disclosure.