Quick Summary
AllegedExecutive Summary
East Texas Family Medicine, a healthcare provider in the United States, was identified as a victim of the Genesis ransomware group, with the listing published on July 5, 2026. This incident was discovered by SOCRadar’s Dark Web Monitoring service. The organization operates within the healthcare sector, which handles sensitive patient data. This listing places East Texas Family Medicine among other US healthcare and small-business entities that Genesis has recently targeted. Over the 60 days preceding this listing, Genesis claimed 32 other victims, with a primary focus on the business services, healthcare, and technology sectors. The majority of its victims are located in the United States, with occasional targets in Jamaica and Canada. Other US healthcare organizations previously targeted by Genesis, similar to East Texas Family Medicine, include Family Medical Associates of Raleigh, The American Board of Preventive Medicine, CarePoint Health, and Mirage Endoscopy Center, indicating a pattern of targeting US clinical practices.
Technical Analysis
SOCRadar’s analysis of stealer-log telemetry revealed a potential initial access vector for East Texas Family Medicine, with exposure noted for the etfmed.com domain. Two credential records indicated targeting of internal infrastructure, specifically a Remote Desktop Web Access (RDP) gateway and an EMR/EHR portal, both hosted on subdomains of the corporate domain. The credentials appeared to be masked account information and were observed across both endpoints, with activity logged between June 25 and July 1, 2026. Credentials harvested by infostealers are a known initial access method for ransomware groups like Genesis. Threat actors often source these credentials from underground markets, validate them for access to systems like Microsoft 365, VPNs, or remote-access portals, and then deploy ransomware. While this specific stealer-log exposure does not definitively confirm Genesis’s use of these credentials, the presence of RDP gateway and EMR/EHR portal credentials aligns with the typical attack chain observed in healthcare ransomware incidents. CTI teams are advised to treat exposed remote-access and clinical portal credentials as an active risk, prioritizing credential rotation, multi-factor authentication, and access log reviews.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.