Quick Summary
AllegedExecutive Summary
INC Ransom has listed Lansing Urgent Care on its dark web portal, marking another incident in the ongoing targeting of US healthcare providers. Lansing Urgent Care operates urgent care clinics within the Lansing, Michigan area. This listing is currently unverified. The healthcare sector remains a significant focus for ransomware groups due to the sensitive nature of patient data and the critical operational impact a disruption can cause. In the preceding 60 days, INC Ransom has claimed 37 victims, predominantly within the Professional Services and Healthcare sectors. The group’s operations show a geographic concentration in the United States, Canada, and Australia. Notable recent victims in the healthcare sector or based in the US include Otter Tail County Minnesota, Stuart & Associates Commercial Flooring Inc., Diabetes and Metabolism Specialists, and Greater Austin Merchants Cooperative Association. Lansing Urgent Care’s profile aligns precisely with INC Ransom’s typical targeting patterns.
Technical Analysis
SOCRadar’s stealer-log telemetry returned no records for the domain lansingurgentcare[.]com within the queried data slice. However, a null result does not constitute confirmation of no compromise. Stealer-log datasets are typically paginated samples, and it is possible that credentials exist in adjacent data slices, under alternate corporate domains, or were captured using employee personal email aliases. INC Ransom commonly sources infostealer-harvested credentials from underground markets. These credentials are used to validate access to systems such as Microsoft 365, VPNs, or remote-access portals before deploying ransomware. Therefore, continued dark web monitoring and proactive credential-hygiene checks, including password rotation and multi-factor authentication review, are recommended to mitigate potential risks.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.