Lansing Urgent Care Data Breach

Alleged

Ransomware claim involving Lansing Urgent Care

Published: Aug 17, 2026 INC Ransom
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Lansing Urgent Care
Industry
Healthcare
Threat Actor
INC Ransom
Date of Incident
Aug 17, 2026

Executive Summary

INC Ransom has listed Lansing Urgent Care on its dark web portal, marking another incident in the ongoing targeting of US healthcare providers. Lansing Urgent Care operates urgent care clinics within the Lansing, Michigan area. This listing is currently unverified. The healthcare sector remains a significant focus for ransomware groups due to the sensitive nature of patient data and the critical operational impact a disruption can cause. In the preceding 60 days, INC Ransom has claimed 37 victims, predominantly within the Professional Services and Healthcare sectors. The group’s operations show a geographic concentration in the United States, Canada, and Australia. Notable recent victims in the healthcare sector or based in the US include Otter Tail County Minnesota, Stuart & Associates Commercial Flooring Inc., Diabetes and Metabolism Specialists, and Greater Austin Merchants Cooperative Association. Lansing Urgent Care’s profile aligns precisely with INC Ransom’s typical targeting patterns.

Technical Analysis

SOCRadar’s stealer-log telemetry returned no records for the domain lansingurgentcare[.]com within the queried data slice. However, a null result does not constitute confirmation of no compromise. Stealer-log datasets are typically paginated samples, and it is possible that credentials exist in adjacent data slices, under alternate corporate domains, or were captured using employee personal email aliases. INC Ransom commonly sources infostealer-harvested credentials from underground markets. These credentials are used to validate access to systems such as Microsoft 365, VPNs, or remote-access portals before deploying ransomware. Therefore, continued dark web monitoring and proactive credential-hygiene checks, including password rotation and multi-factor authentication review, are recommended to mitigate potential risks.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.