Interlock, a ransomware group, says it took 710 GB of data from AngMar Management Services, a Mansfield, Texas company that runs business operations for home health and hospice providers. The breach now sits on the federal health-breach portal at 126,196 individuals, and the data involved reaches well past names: Social Security numbers, diagnoses and prescriptions are on the list.
The intrusion is dated to about July 18, 2026, with AngMar noticing unusual network activity on July 20. A data review finished on September 8, and the public tally has grown in the weeks since, which is why the 126,196 count matters more than the first state filing did. The Texas Attorney General figure of 35,916 residents covers only part of the people involved; the rest live elsewhere in the country.
The Interlock leak-site claim and its 710 GB
On August 11, 2026, Interlock posted a claim to its dark web leak site saying it had taken “710 GB of the organization’s data,” according to the breach tracker ClaimDepot. The HIPAA Journal describes the incident as appearing to be an Interlock ransomware attack and repeats the 710 GB figure as the group’s own claim. SecurityWeek, in its report on the AngMar and Clover Health disclosures, quoted the group as saying “over 700 gigabytes,” so the exact size depends on which post is read.
The number is an assertion by the attackers, not an audited measure. Paubox’s write-up of the Texas hospice company attack notes that Interlock posted a screenshot of folders it says came from AngMar, that the data’s authenticity has not been verified, and that the group’s posted note suggests AngMar did not pay.
The 126,196 count and the Texas share
The national total comes from the Department of Health and Human Services breach portal. SecurityWeek reported that AngMar told HHS on September 16 that 126,196 individuals were affected, and the HIPAA Journal’s update says the Office for Civil Rights portal now lists that figure. Separately, a filing with the Texas Attorney General put 35,916 Texas residents among those potentially affected, a subset of the national total rather than a second breach.
Federal rules explain why the portal exists. Under the HHS Breach Notification Rule, a breach touching 500 or more people must be reported to the Secretary within 60 days of discovery, and HHS publishes those cases publicly. Paubox cites a September 22 notice to the Massachusetts Attorney General, so patients outside Texas were being written to as well.
Medical and Social Security data on the exposure list
The list is long and clinical. According to the HIPAA Journal, the information includes names, addresses, dates of birth, Social Security numbers, patient and medical record numbers, health insurance details, dates of service, provider names, diagnosis or condition information, prescription information and medical history. Not every person had every element, a point Paubox makes by describing the data as involved “for some patients.”
The mix is what makes a healthcare record more durable than a stolen card number. A Social Security number can be reissued only in narrow cases, and a diagnosis cannot be changed at all, so the information stays usable for fraud and targeted scams long after the incident. AngMar is offering complimentary single-bureau monitoring through Cyberscout, with enrollment due within 90 days of the notice letter and an assistance line at 1-877-520-9311, ClaimDepot reports.
Interlock’s double-extortion method in the CISA advisory
The federal joint advisory from CISA, the FBI and partners describes Interlock as first observed in late September 2024, with the FBI calling its actors “opportunistic and financially motivated.” The group steals data before encrypting systems, then threatens to publish it on a Tor leak site, and the advisory notes it has followed through on that threat before.
The AngMar timeline fits the pattern the advisory lays out: a mid-July intrusion, a leak-site listing in August, and public notification only after the September review, roughly two months after the attackers were inside. Interlock’s targeting, in CISA’s words, spans businesses and critical infrastructure in North America and Europe, and the advisory was co-authored by HHS, which directs healthcare organizations to its sector-specific cybersecurity performance goals. The advisory lists drive-by downloads from compromised sites and the ClickFix fake-CAPTCHA trick among its entry methods, though none of the AngMar reports say how Interlock got into this network.
Which AngMar client practices sit behind the 126,196 records has not been published. The HIPAA Journal and SecurityWeek both identify only AngMar itself, so patients of the home health and hospice agencies it supports will most likely learn of their own inclusion from the notice letter rather than from the portal. The distinction matters because a management company holds records on behalf of many care providers, and a single intrusion at that layer can reach patients of agencies that never saw a problem on their own systems.
This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.
More from Morning Overview
- Doctors warn a silent liver disease now affects one in three American adults
- The FBI told the rest of ShinyHunters to surrender after a 24-year-old was arrested
- Two passengers died at an Ohio toll plaza, and the NTSB now wants the cash lanes shut
- Long use of a common prostate pill is tied to a higher chance of glaucoma