Chaos Ransomware Group Claims 235GB PHI/Internal Document Leak from Healthcare Highways (Unconfirmed)

Chaos Ransomware Group Claims 235GB PHI/Internal Document (TL-2026-2045) is a high-severity ransomware operation, first published 2026-08-17. It is attributed to Chaos with medium confidence, affects Healthcare Highways, Inc. Corporate IT environment / provider-network, maps to 18 MITRE ATT&CK techniques (T1005, T1021.001, T1027), and is covered by 9 detection rules and 19 indicators of compromise.

Key facts for TL-2026-2045

Threat ID
TL-2026-2045
Severity
HIGH
Status
ACTIVE
Category
RANSOMWARE
First published
2026-08-17
Last reviewed
2026-08-17
Attribution
Chaos
Attribution confidence
MEDIUM
Motivation
FINANCIAL
Target sectors
health, health insurance, healthcare network administration
Target regions
united states of america, Texas, Oklahoma, Louisiana, Ohio
Detection rules
9
Indicators of compromise
19

Malware and tooling in Chaos Ransomware Group Claims 235GB PHI/Internal Document

Malware and tooling: AnyDesk, Chaos, Dataleak, AnyDesk, ClamAV:Win.Ransomware.Chaos-10045485-0, GoodSync, Impacket atexec, Microsoft Quick Assist, OptiTune, ScreenConnect, Snort SIDs 65125, 65126 (Snort2); 301273 (Snort3), Splashtop

On August 4, 2026 the Chaos ransomware-as-a-service (RaaS) group posted healthcarehighways.com to its Tor leak site, claiming exfiltration of 235GB of company and client records — including SSNs and health-insurance claims data — from Healthcare Highways, Inc. (HCH), a Frisco, TX-based network administrator serving 12,000+ primary care physicians, 69,000+ specialists, and 3,000+ facilities across TX, OK, LA and OH. A 24-hour contact deadline was set before threatened publication. HCH has not confirmed the breach.

How Chaos Ransomware Group Claims 235GB PHI/Internal Document works

Chaos is a ransomware-as-a-service group first observed in early-to-mid February 2025 that Cisco Talos assesses, with moderate confidence, is likely operated by former members of the BlackSuit/Royal gang following a July 24, 2025 DOJ-led international law-enforcement action that seized BlackSuit's infrastructure — based on matching encryption command-line parameters (/lkey, /encrypt_step, /kill_vms), ransom-note structure, and toolset overlap. Chaos runs opportunistic, big-game-hunting double (and observed triple/quadruple) extortion operations, advertising affiliate recruitment on the Russian-language RAMP (Ransom Anon Market Place) forum, and per its own operator statements avoids BRICS/CIS countries, hospitals, and government entities as targets — notable here because Healthcare Highways is a healthcare network *administrator* rather than a direct hospital operator.

On 2026-08-04 at 15:57 UTC, Chaos posted a leak-site entry for healthcarehighways.com claiming 235GB of 'sensitive company and client records' were taken, with a 24-hour countdown for corporate contact before threatened publication; dark-web trackers (ransomware.live) and OSINT aggregators (RedPacketSecurity) subsequently indexed and republished the claim. Follow-on legal reporting (ClassAction.org, Levi & Korsinsky, Bryson Harris Suciu & DeMay PLLC) describes the allegedly compromised data as including names/contact information, Social Security numbers, and health/medical information tied to health-insurance claims processing — consistent with HCH's role administering employer health plans and provider networks. As of 2026-08-17, Healthcare Highways has not confirmed or denied the incident, no ransom amount specific to this victim has been disclosed, no data sample or leak publication has been observed, and no CVE/initial-access vector has been confirmed for this specific intrusion.

Because the intrusion vector for the HCH claim itself is not yet confirmed, the MITRE ATT&CK techniques below reflect Chaos's well-documented group-level tradecraft (Cisco Talos, AttackIQ, Rapid7) rather than victim-specific forensic findings: initial access via spam-flood-driven voice phishing (vishing) that walks victims into launching Microsoft Quick Assist for attacker-controlled remote access; persistence and lateral movement via abused legitimate RMM tools (AnyDesk, ScreenConnect, Splashtop, Syncro RMM, OptiTune) and RDP; command execution via PowerShell, WMI, and Impacket's atexec; data exfiltration using the legitimate GoodSync file-sync utility renamed to masquerade as wininit.exe; and impact via selective ECDH(Curve25519)+AES-256 file encryption (appending .chaos, dropping readme.chaos.txt) preceded by Volume Shadow Copy deletion. Analysts should also be aware that at least one unrelated Chaos-branded intrusion was assessed by Rapid7 (2026-05-06) as a false-flag operation by the Iranian APT MuddyWater (Seedworm) — underscoring that 'Chaos' leak-site attribution alone does not guarantee a single consistent actor or toolset behind every claim carrying the brand, and reinforcing why this HCH claim remains treated as unconfirmed pending forensic corroboration.

MITRE ATT&CK techniques used in TL-2026-2045

Collection

T1005 Data from Local System

Lateral Movement

T1021.001 Remote Services: Remote Desktop Protocol

Defense Evasion

T1027 Obfuscated Files or Information; T1036.005 Match Legitimate Resource Name or Location; T1497 Virtualization/Sandbox Evasion

Execution

T1047 Windows Management Instrumentation; T1053.002 At; T1059.001 Command and Scripting Interpreter: PowerShell

Discovery

T1057 Process Discovery; T1135 Network Share Discovery

Initial Access

T1078 Valid Accounts; T1566.004 Phishing: Spearphishing Voice

Persistence

T1133 External Remote Services; T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder

Command and Control

T1219 Remote Access Tools

Impact

T1490 Inhibit System Recovery

Exfiltration

T1567.002 Exfiltration Over Web Service: Exfiltration to Cloud Storage

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in Chaos Ransomware Group Claims 235GB PHI/Internal Document

  • Healthcare Highways, Inc. — Corporate IT environment / provider-network and claims-administration systems (Frisco, TX HQ; operations in TX, OK, LA, OH)

Remediation for Chaos Ransomware Group Claims 235GB PHI/Internal Document

Immediate actions

  • Treat the Chaos leak-site claim against Healthcare Highways as a credible incident until forensically disproven; engage incident response and breach counsel immediately.
  • Hunt for unauthorized/unexpected Microsoft Quick Assist sessions and unmanaged RMM installs (AnyDesk, ScreenConnect, Splashtop, Syncro RMM, OptiTune, DWAgent) across the environment.
  • Search for GoodSync binaries — especially any renamed to wininit.exe or other system-process names — and for large outbound transfers to cloud-sync endpoints or reverse SSH tunnels.
  • Force credential resets and MFA re-registration for privileged/domain-admin accounts; review recently enrolled MFA devices for unauthorized additions.
  • Monitor Chaos's Tor leak site and dark-web trackers (ransomware.live) for publication or removal of the claimed 235GB Healthcare Highways dataset.

Workarounds

  • Restrict or disable Microsoft Quick Assist except via a monitored, ticket-gated allow-list.
  • Block outbound connections to known Chaos C2 infrastructure (45.61.134.36:443; onion gateways for the group's leak sites) at the perimeter/proxy.

Longer-term hardening

  • Deploy phishing-resistant MFA and restrict/disable Microsoft Quick Assist enterprise-wide except through a monitored helpdesk allow-list.
  • Implement RMM governance/application allow-listing so only sanctioned remote-access tools can install and execute.
  • Deploy EDR tuned for Volume Shadow Copy deletion, mass file rename/encryption, and Impacket-style remote execution (atexec, wmiexec).
  • Segment and monitor claims/PHI data stores; apply DLP on egress channels (cloud sync, SFTP) that handle PHI/PII.
  • Run organization-wide vishing and helpdesk-impersonation social-engineering awareness training.

Timeline of Chaos Ransomware Group Claims 235GB PHI/Internal Document

  • Chaos RaaS first observed in the wild (Cisco Talos, RansomLook, AttackIQ all date group emergence to early-to-mid February 2025).
  • DOJ-led international law-enforcement action seizes BlackSuit ransomware infrastructure; researchers cite this as the likely catalyst for former BlackSuit/Royal members reorganizing as Chaos.
  • Cisco Talos publishes 'Unmasking the new Chaos RaaS group attacks,' detailing TTPs, encryption command-line parameters, and moderate-confidence BlackSuit/Royal lineage assessment.
  • AttackIQ publishes a detailed Chaos ransomware technical/detection profile describing continued RaaS resurgence and confirming BlackSuit-linked tooling.
  • Dark-web monitoring platforms (ransomware.live, HookPhish) and OSINT aggregators (RedPacketSecurity) index and republish the Chaos claim against Healthcare Highways.
  • At 15:57 UTC, Chaos posts healthcarehighways.com to its Tor leak site, claiming exfiltration of 235GB of sensitive company and client records and setting a 24-hour contact deadline before threatened publication.
  • As of this reporting, Healthcare Highways has not confirmed or denied the breach; no ransom figure specific to this victim, data sample, or leak publication has been observed.
  • ClassAction.org (via Bryson Harris Suciu & DeMay PLLC) and Levi & Korsinsky, LLP publish investigations soliciting affected Healthcare Highways patients, staff, and providers for potential class-action litigation.

Sources cited for Chaos Ransomware Group Claims 235GB PHI/Internal Document

Threats related to Chaos Ransomware Group Claims 235GB PHI/Internal Document

Detection coverage for TL-2026-2045

As of 2026-08-17, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2045 across Splunk SPL, Microsoft KQL and Sigma, covering 19 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats