Hospitality Health ER (Longview) Data Breach

Alleged

Ransomware claim involving Hospitality Health ER (Longview).

Published: Aug 23, 2026 Genesis
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Hospitality Health ER (Longview)
Industry
Healthcare
Threat Actor
Genesis
Date of Incident
Aug 23, 2026

Executive Summary

Hospitality Health ER (Longview), a healthcare provider based in the United States, was identified on the Genesis ransomware group’s leak site on August 23, 2026. This organization specializes in emergency medical services within the Longview region. The inclusion of a US healthcare entity on Genesis’s victim list is notable, as the group has a demonstrated history of targeting the healthcare sector. Over the preceding 60 days, Genesis has claimed approximately 23 victims, with the Healthcare, Technology, and Manufacturing industries being its most frequently targeted sectors. The United States, Denmark, and Canada are among the countries most frequently affected by this group. While this specific listing does not have a direct parallel to other identified Genesis victims that are exclusively US emergency care facilities, the group’s consistent focus on healthcare aligns with its typical targeting strategies. This incident is consistent with the group’s operational patterns.

Technical Analysis

A review of SOCRadar’s stealer-log telemetry data for the domain hher24.com yielded no records within the queried sample. It is crucial to note that a lack of findings in this specific, paginated dataset does not confirm the organization’s immunity to compromise. The search did not encompass alternate corporate domains, personal email aliases that might be used for corporate access, or credentials that may have been utilized and subsequently rotated before being indexed in the analyzed feeds. Infostealer-harvested credentials are a primary vector for initial access for many ransomware operations. While no direct evidence linking stealer logs to Hospitality Health ER (Longview) was found in this particular query, the absence of data from a limited sample does not rule out the possibility of compromised credentials being used. Genesis, like many other ransomware groups, commonly exploits various entry points, including phishing campaigns, exposed VPN appliances, and the reuse of compromised credentials. Affected organizations are strongly advised to conduct thorough audits of their authentication logs, implement multi-factor authentication on all internet-facing services, and consider this leak-site listing as a significant indicator of potential compromise or at least substantial threat actor reconnaissance. Proactive monitoring for additional indicators of compromise and a review of credential hygiene practices remain essential.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.