Chaos Ransomware Group Claims 235GB PHI/Internal Document Leak from Healthcare Highways (Unconfirmed) — Threadlinqs Intelligence
As of 2026-08-17, Chaos Ransomware Group Claims 235GB PHI/Internal Document Leak from Healthcare Highways (Unconfirmed) is a high-severity ransomware threat attributed to Chaos, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 19 indicators of compromise.
Threat ID: TL-2026-2045 · Severity: HIGH · Status: ACTIVE · Category: RANSOMWARE
Attribution: Chaos · FINANCIAL
On August 4, 2026 the Chaos ransomware-as-a-service (RaaS) group posted healthcarehighways.com to its Tor leak site, claiming exfiltration of 235GB of company and client records — including SSNs and
Chaos is a ransomware-as-a-service group first observed in early-to-mid February 2025 that Cisco Talos assesses, with moderate confidence, is likely operated by former members of the BlackSuit/Royal gang following a July 24, 2025 DOJ-led international law-enforcement action that seized BlackSuit's infrastructure — based on matching encryption command-line parameters (/lkey, /encrypt_step, /kill_vms), ransom-note structure, and toolset overlap. Chaos runs opportunistic, big-game-hunting double (and observed triple/quadruple) extortion operations, advertising affiliate recruitment on the Russian-language RAMP (Ransom Anon Market Place) forum, and per its own operator statements avoids BRICS/CIS countries, hospitals, and government entities as targets — notable here because Healthcare Highways is a healthcare network *administrator* rather than a direct hospital operator.
On 2026-08-04 at 15:57 UTC, Chaos posted a leak-site entry for healthcarehighways.com claiming 235GB of 'sensitive company and client records' were taken, with a 24-hour countdown for corporate contact before threatened publication; dark-web trackers (ransomware.live) and OSINT aggregators (RedPacketSecurity) subsequently indexed and republished the claim. Follow-on legal reporting (ClassAction.org, Levi & Korsinsky, Bryson Harris Suciu & DeMay PLLC) describes the allegedly compromised data as including names/contact information, Social Security numbers, and health/medical information tied to health-insurance claims processing — consistent with HCH's role administering employer health plans and provider networks. As of 2026-08-17, Healthcare Highways has not confirmed or denied the incident, no ransom amount specific to this victim has been disclosed, no data sample or leak publication has been observed, and no CVE/initial-access vector has been confirmed for this specific intrusion.
Because the intrusion vector for the HCH claim itself is not yet confirmed, the MITRE ATT&CK techniques below reflect Chaos's well-documented group-level tradecraft (Cisco Talos, AttackIQ, Rapid7) rather than victim-specific forensic findings: initial access via spam-flood-driven voice phishing (vishing) that walks victims into launching Microsoft Quick Assist for attacker-controlled remote access; persistence and lateral movement via abused legitimate RMM tools (AnyDesk, ScreenConnect, Splashtop, Syncro RMM, OptiTune) and RDP; command execution via PowerShell, WMI, and Impacket's atexec; data exfiltration using the legitimate GoodSync file-sync utility renamed to masquerade as wininit.exe; and impact via selective ECDH(Curve25519)+AES-256 file encryption (appending .chaos, dropping readme.chaos.txt) preceded by Volume Shadow Copy deletion. Analysts should also be aware that at least one unrelated Chaos-branded intrusion was assessed by Rapid7 (2026-05-06) as a false-flag operation by the Iranian APT MuddyWater (Seedworm) — underscoring that 'Chaos' leak-site attribution alone does not guarantee a single consistent actor or toolset behind every claim carrying the brand, and reinforcing why this HCH claim remains treated as unconfirmed pending forensic corroboration.
Target sectors: health, health insurance, healthcare network administration
Target regions: united states of america, Texas, Oklahoma, Louisiana, Ohio
Timeline
- Chaos RaaS first observed in the wild (Cisco Talos, RansomLook, AttackIQ all date group emergence to early-to-mid February 2025).
- DOJ-led international law-enforcement action seizes BlackSuit ransomware infrastructure; researchers cite this as the likely catalyst for former BlackSuit/Royal members reorganizing as Chaos.
- Cisco Talos publishes 'Unmasking the new Chaos RaaS group attacks,' detailing TTPs, encryption command-line parameters, and moderate-confidence BlackSuit/Royal lineage assessment.
- AttackIQ publishes a detailed Chaos ransomware technical/detection profile describing continued RaaS resurgence and confirming BlackSuit-linked tooling.
- At 15:57 UTC, Chaos posts healthcarehighways.com to its Tor leak site, claiming exfiltration of 235GB of sensitive company and client records and setting a 24-hour contact deadline before threatened publication.
- Dark-web monitoring platforms (ransomware.live, HookPhish) and OSINT aggregators (RedPacketSecurity) index and republish the Chaos claim against Healthcare Highways.
- ClassAction.org (via Bryson Harris Suciu & DeMay PLLC) and Levi & Korsinsky, LLP publish investigations soliciting affected Healthcare Highways patients, staff, and providers for potential class-action litigation.
- As of this reporting, Healthcare Highways has not confirmed or denied the breach; no ransom figure specific to this victim, data sample, or leak publication has been observed.
Detections & IOCs
As of 2026-09-06, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 19 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
RANSOMWARE, HIGH, threat intelligence, cybersecurity, T1566.004, T1078, T1133, T1547.001, T1059.001, T1053.002, T1047, T1036.005, T1027, T1685