DaVita Settles $15M Class Action Over Interlock Ransomware Breach Affecting 2.7M Patients
DaVita Settles $15M Class Action Over Interlock Ransomware (TL-2026-2328) is a high-severity data breach, first published 2026-09-04. It is attributed to Interlock with medium confidence, affects DaVita Inc. DaVita dialysis and laboratory network infrastructure, maps to 15 MITRE ATT&CK techniques (T1021.001, T1036.005, T1056.001), and is covered by 9 detection rules and 21 indicators of compromise.
Key facts for TL-2026-2328
- Threat ID
- TL-2026-2328
- Severity
- HIGH
- Status
- RESOLVED
- Category
- DATA_BREACH
- First published
- 2026-09-04
- Last reviewed
- 2026-09-04
- Attribution
- Interlock
- Attribution confidence
- MEDIUM
- Motivation
- FINANCIAL
- Target sectors
- health, dialysis and renal care, medical laboratories
- Target regions
- united states of america
- Detection rules
- 9
- Indicators of compromise
- 21
Malware and tooling in DaVita Settles $15M Class Action Over Interlock Ransomware
Malware and tooling: Berserk Stealer, Cobalt Strike, Lumma Stealer - S1213, NodeSnake RAT, STOP Ransomware, SystemBC - S9001, interlock, AnyDesk, AzCopy, Azure Storage Explorer (StorageExplorer.exe), Cobalt Strike, Interlock RAT
Dialysis provider DaVita agreed to pay $15 million to settle a consolidated federal class action (Jenkins, et al. v. DaVita Inc., D. Colorado, No. 1:25-cv-01358-SBP) over an April 2025 Interlock ransomware double-extortion attack that compromised the data of 2,689,826 individuals. The court granted preliminary settlement approval on August 21, 2026, with a final approval hearing scheduled for 2027.
How DaVita Settles $15M Class Action Over Interlock Ransomware works
On March 24, 2025, the Interlock ransomware group gained unauthorized access to the network of DaVita Inc., a Denver-based dialysis and kidney care provider operating 2,675 outpatient centers across the United States and holding roughly 37% of the U.S. dialysis market. The intrusion went undetected for roughly three weeks until DaVita identified anomalous activity on April 12, 2025, activated its incident response plan, and proactively disconnected affected network segments, eradicating the threat actor from its environment the same day it was discovered. DaVita disclosed the incident via SEC Form 8-K on April 14, 2025, and publicly announced it on April 18, 2025.
Interlock employed its characteristic double-extortion model: exfiltrating data before deploying ransomware to encrypt files on portions of DaVita's network, primarily affecting laboratory database infrastructure. When DaVita did not pay the ransom, the group began publishing the stolen data on its Tor-based dark web leak site starting April 24-25, 2025, claiming to have exfiltrated roughly 1.5 TB (spanning over 683,000 files and 75,000 folders, individual folders ranging from 55 MB to over 1 TB), including internal documents, spreadsheets, and screenshots of sensitive records. DaVita's investigation, reported to the HHS Office for Civil Rights breach portal on August 1, 2025 and finalized around August 22, 2025, confirmed that 2,689,826 individuals were affected, making it one of the largest healthcare data breaches reported in 2025. Compromised data included patient names, addresses, dates of birth, Social Security numbers, health insurance information, dialysis lab test results and other health/clinical information, tax identification numbers, and in limited cases images of checks written to DaVita. Patient care reportedly continued uninterrupted throughout the incident; DaVita separately disclosed roughly $13.5 million in Q2 2025 incident costs ($12.5M remediation, $1.0M increased patient-care costs) against a reported total 2025 cost of the incident of about $25 million.
On July 22, 2025, CISA, the FBI, HHS, and MS-ISAC jointly published advisory AA25-203A (#StopRansomware: Interlock), documenting the group's TTPs from investigations through June 2025: initial access via drive-by downloads (malicious payloads disguised as fake Chrome/Edge browser updates or fake security-software updates for products such as FortiClient, Ivanti, GlobalProtect, Webex, and Cisco Secure Client) and ClickFix-style social engineering that tricks users into pasting and executing Base64-encoded PowerShell via the Windows Run dialog; deployment of a credential stealer (cht.exe) and keylogger (klg.dll, logging to conhost.txt); persistence via Startup-folder entries or a registry Run key disguised as a 'Chrome Updater' that re-executes a RAT on every logon; credential theft via browser credential dumping and Kerberoasting against domain accounts; lateral movement via RDP, AnyDesk, PuTTY, and cracked ScreenConnect instances; data staging and exfiltration to attacker-controlled Azure Blob Storage via Azure Storage Explorer and AzCopy, or alternatively via WinSCP; and file encryption using a 64-bit AES/RSA binary (conhost.exe) that appends .interlock or .1nt3rlock extensions and drops a !__README__!.txt ransom note (delivered via Group Policy Object) directing victims to a Tor .onion negotiation site, with no upfront ransom figure stated. It is not publicly confirmed which specific initial-access vector was used against DaVita; the TTPs above reflect Interlock's documented pattern of operations across its victim set generally, not DaVita-specific forensic disclosure.
The breach generated at least ten separate class-action lawsuits against DaVita, consolidated in the U.S. District Court for the District of Colorado as Jenkins, et al. v. DaVita Inc. (Case No. 1:25-cv-01358-SBP), alleging negligence, breach of implied contract, unjust enrichment, breach of fiduciary duty, invasion of privacy, and state consumer-protection violations. On August 21, 2026, the court granted preliminary approval of a $15 million settlement: $10 million earmarked for class-member relief (claims of up to $2,500 for documented losses, with a projected average payout of roughly $50 per claimant depending on response rates), with the remainder covering attorneys' fees, administrative costs, and service awards. DaVita denied all liability and wrongdoing. A final settlement approval hearing is scheduled for 2027.
MITRE ATT&CK techniques used in TL-2026-2328
Lateral Movement
T1021.001 Remote Services: Remote Desktop Protocol
Defense Evasion
T1036.005 Match Legitimate Resource Name or Location; T1218.011 System Binary Proxy Execution: Rundll32
Credential Access
T1056.001 Input Capture: Keylogging; T1555.003 Credentials from Password Stores: Credentials from Web Browsers; T1558.003 Steal or Forge Kerberos Tickets: Kerberoasting
Execution
T1059.001 Command and Scripting Interpreter: PowerShell; T1204.004 User Execution: Malicious Copy and Paste
Privilege Escalation
T1078.002 Valid Accounts: Domain Accounts
Discovery
T1082 System Information Discovery
Command and Control
Collection
Persistence
T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
Exfiltration
T1567.002 Exfiltration Over Web Service: Exfiltration to Cloud Storage
Impact
Affected products and versions in DaVita Settles $15M Class Action Over Interlock Ransomware
- DaVita Inc. — DaVita dialysis and laboratory network infrastructure
Vulnerable versions: Network environment accessed by Interlock actors March 24 - April 12, 2025
Fixed in: Threat actor eradicated and affected network segments remediated as of April 12, 2025
Remediation for DaVita Settles $15M Class Action Over Interlock Ransomware
Patches
- Prioritize patching internet-facing systems and known exploited vulnerabilities per the CISA KEV catalog
Immediate actions
- Isolate and disconnect affected network segments to contain lateral movement, as DaVita did on April 12, 2025
- Reset credentials for all domain and privileged accounts observed or suspected to be compromised, including hunting for Kerberoasting activity
- Hunt for known Interlock artifacts across the estate: cht.exe, klg.dll, conhost.txt, .interlock/.1nt3rlock encrypted files, and !__README__!.txt ransom notes
Workarounds
- Train users to recognize ClickFix-style fake CAPTCHA prompts and fake browser/security-software update lures used by Interlock for initial access
- Restrict or allowlist remote access/administration tools (AnyDesk, ScreenConnect, PuTTY) to prevent abuse for lateral movement and persistence
Longer-term hardening
- Deploy DNS filtering and web-access firewalls to block drive-by-download and malicious fake-update infrastructure
- Implement phishing-resistant MFA on all critical, remote-access, and administrative services
- Enforce network segmentation between clinical/laboratory systems and corporate IT
- Deploy EDR tooling on all endpoints, servers, and virtual machines, including laboratory infrastructure
- Maintain offline, encrypted, immutable backups and regularly test restoration procedures
- Audit and enforce least privilege on administrative and domain accounts to reduce Kerberoasting exposure
Timeline of DaVita Settles $15M Class Action Over Interlock Ransomware
- Interlock ransomware actors gain unauthorized access to DaVita's network; the intrusion goes undetected for roughly three weeks
- DaVita detects the ransomware activity, activates incident response protocols, proactively disconnects affected network segments, and eradicates the threat actor from its environment the same day
- DaVita discloses the cybersecurity incident via SEC Form 8-K filing
- DaVita publicly announces the ransomware incident
- Interlock ransomware group publicly claims responsibility and begins publishing roughly 1.5 TB of stolen DaVita data on its Tor dark web leak site after ransom demands go unmet
- CISA, FBI, HHS, and MS-ISAC jointly publish advisory AA25-203A (#StopRansomware: Interlock), detailing the group's TTPs and IOCs from investigations through June 2025
- DaVita reports the breach to the HHS Office for Civil Rights breach portal
- DaVita finalizes confirmation that 2,689,826 individuals were affected, ranking the incident among the largest healthcare data breaches reported in 2025
- U.S. District Court for the District of Colorado grants preliminary approval of the $15 million class settlement in Jenkins, et al. v. DaVita Inc. (No. 1:25-cv-01358-SBP)
- Settlement terms are publicly reported, including the $15M total, $10M class-relief allocation, and claims of up to $2,500 per documented loss
Sources cited for DaVita Settles $15M Class Action Over Interlock Ransomware
- DaVita Agrees to Pay $15 Million to Settle Data Breach Litigation
- DaVita agrees to pay $15M to settle claims from data breach
- #StopRansomware: Interlock (AA25-203A)
- DaVita Confirms 2.7 Million Individuals Affected by Ransomware Attack
- Interlock Ransomware Group Claims DaVita Attack, Leaks Over 1.5 TB of Data
- Interlock ransomware gang started leaking data allegedly stolen from leading kidney dialysis firm DaVita
More in data breach
- Condé Nast Data Breach: 32.8 Million User Records Offered for Sale Following WIRED Leak
- Coordinated GitHub API Enumeration and Access Token Abuse Campaign
- PEAR ransomware group claims data leak from South Plains Rural Health Services (SPRHS)
- ShinyHunters Extortion Group Claims 284M-Record McKesson Corporation Data Breach via Vishing and Salesforce/Snowflake Compromise
- Qilin Ransomware Gang Claims Breach of US ATF; Agency Confirms 'Major Incident' on Isolated Investigations System
Detection coverage for TL-2026-2328
As of 2026-09-04, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2328 across Splunk SPL, Microsoft KQL and Sigma, covering 21 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.