VORANT. Threat Intelligence Sign in Get the full feed

Genesis ransomware claims Memphis medical practice

elevated threat healthcare

Ransomware group Genesis lists Consolidated Medical Practices of Memphis as a victim, exposing compromised user and third-party credential data.

Ransomware.live has indexed a leak-site listing attributed to a group tracked as "Genesis" naming Consolidated Medical Practices of Memphis as a victim. The posting, sourced from publicly visible leak-site data rather than exfiltrated content itself, references 394 compromised users and 188 third-party employee credentials, alongside a small external attack surface of three assets.

No technical details on the intrusion vector, ransomware payload, or extortion demands are provided in this listing. Given the target is a healthcare provider, exposure of user and credential data raises concerns around patient privacy and further credential-based attacks against the organization or its partners, though the scale and impact remain unconfirmed beyond the leak-site claim.

Mentioned in this report

Threat actors genesis
Malware Genesis

Source reporting: https://www.ransomware.live/id/Q29uc29saWRhdGVkIE1lZGljYWwgUHJhY3RpY2VzIG9mIE1lbXBoaXNAZ2VuZXNpcw==

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free