# Genesis ransomware claims Memphis medical practice

Published: 2026-08-10 · Severity: elevated · Sectors: healthcare
Canonical: https://vorant.io/reports/9ccf11a0-567f-56de-bbdf-f05395fb258d/genesis-ransomware-claims-memphis-medical-practice

> Ransomware group Genesis lists Consolidated Medical Practices of Memphis as a victim, exposing compromised user and third-party credential data.

Ransomware.live has indexed a leak-site listing attributed to a group tracked as "Genesis" naming Consolidated Medical Practices of Memphis as a victim. The posting, sourced from publicly visible leak-site data rather than exfiltrated content itself, references 394 compromised users and 188 third-party employee credentials, alongside a small external attack surface of three assets.

No technical details on the intrusion vector, ransomware payload, or extortion demands are provided in this listing. Given the target is a healthcare provider, exposure of user and credential data raises concerns around patient privacy and further credential-based attacks against the organization or its partners, though the scale and impact remain unconfirmed beyond the leak-site claim.

## Mentioned in this report

- Threat actors: genesis
- Malware: Genesis

Source reporting: https://www.ransomware.live/id/Q29uc29saWRhdGVkIE1lZGljYWwgUHJhY3RpY2VzIG9mIE1lbXBoaXNAZ2VuZXNpcw==

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/9ccf11a0-567f-56de-bbdf-f05395fb258d/genesis-ransomware-claims-memphis-medical-practice.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
