Quick Summary
AllegedExecutive Summary
Integrex RCM, a US-based revenue cycle management firm specializing in healthcare billing, coding, and administrative services, was listed on the Qilin ransomware group’s dark web portal on August 26, 2026. This listing was identified through SOCRadar’s Dark Web Monitoring service and has not been independently verified. The company’s focus on handling sensitive patient and financial data makes it a potentially attractive target for ransomware operations. In the 60 days preceding this listing, the Qilin ransomware group claimed 217 victims, predominantly in the Manufacturing, Professional Services, and Technology sectors, with the United States being the most frequently targeted country. This incident aligns with a broader trend of increased attacks against US professional services firms in mid-2026, with other notable victims including Clear Align, The Pendas Law Firm, White-Daters & Associates, Inc., and Arnall Golden Gregory. Integrex RCM’s operations at the intersection of healthcare administration and financial data present a compounded risk due to their access to billing records, patient identifiers, and insurance claim data.
Technical Analysis
SOCRadar’s stealer-log telemetry returned no records for the domain integrexhealth[.]com within the queried sample. It is important to note that this query covered a paginated slice of indexed logs. The absence of records in this specific dataset does not definitively confirm that the organization is unaffected. Potential exposure could still exist in data feeds outside of this queried dataset, under alternate domain variants, or through credentials tied to personal email aliases used by employees. Qilin and its associated initial access brokers are known to source credentials from underground markets. These credentials are then validated against corporate portals, and subsequently utilized for pre-ransomware staging and deployment. The null result from the stealer-log telemetry does not rule out this potential intrusion path. Organizations are advised to continue monitoring integrexhealth[.]com across additional threat intelligence feeds and to rigorously enforce credential hygiene practices, with a particular emphasis on accounts that have access to sensitive systems such as billing and patient-record management.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.