Cyber & AI intelligence
Wasteland.
Briefs indexed2967
Issues30
Published Mondays07:30 CT
▣ Breach ANGMAR-MANAGEMENT- 2026-10-02

AngMar Management Services: Interlock Ransomware Claims Hospice Manager Breach

"AngMar Management Services has confirmed that an unauthorized actor got into its IT systems and may have accessed or taken patient files. AngMar is a home health and hospice management company in Mansfield, Texas. A…"

AngMar Management Services has confirmed that an unauthorized actor got into its IT systems and may have accessed or taken patient files. AngMar is a home health and hospice management company in Mansfield, Texas. A filing with the Texas Attorney General puts the number of affected Texas residents at 35,916, according to HIPAA Journal. Other state filings add small counts: 9 New Hampshire residents (per Edelson Lechtzin LLP) and 3 Massachusetts residents (per Federman & Sherwood). The total number of people affected nationwide has not been disclosed. The Interlock ransomware group listed AngMar on its dark web leak site in August and says it stole 710 GB of data. AngMar's notification letter does not name an attacker or mention ransomware.

What Happened

AngMar's notification letter and HIPAA Journal's reporting agree on the main timeline:

The sources disagree on some dates. HIPAA Journal says the data review was completed on September 8. Edelson Lechtzin and Class Action U both say September 10. For notifications, Edelson Lechtzin says AngMar notified individuals and regulators "on or about September 10," while Class Action U says letters started going out on September 22.

One account contradicts the rest. Edelson Lechtzin's press release (republished by NY Business Times) says the breach happened "on or about July 31, 2026" and that "an employee accidentally emailed documents to an unauthorized actor." Both claims conflict with AngMar's own letter, which gives July 18 as the access date and July 20 as the detection date and describes unusual network activity, not a misdirected email. The same release also lists "financial details" among the exposed data, which the letter does not include. The details look like they may have come from a different incident. We treat them as unverified.

AngMar was founded in 2000 and handles back-office work, clinical compliance, and business development for home health and hospice agencies. Class Action U reports that it manages close to 100 locations in eleven states under brands including Angels Care Home Health. The breach therefore likely reaches beyond Texas, and the 35,916 figure should be read as a floor, not a total.

What Was Taken

According to AngMar's notification letter, the affected data may have included a person's first and last name plus any of the following:

Claim Depot adds "medical records" to the list. Edelson Lechtzin adds "financial details." Neither item appears in the company's letter.

Interlock claims it took 710 GB of data. That figure comes from the attackers and has not been independently verified. AngMar has not confirmed that anything was exfiltrated. It says only that data "may have been accessed or acquired," and that there is "no evidence to suggest" misuse so far. The letter came via Cyberscout, which suggests that is the provider of the free credit monitoring AngMar is offering.

Why It Matters

This is a third-party risk problem. AngMar is a management company, not a care provider. It runs back-office and compliance work for many agencies, so one intrusion exposed patient data from agencies across several states. Healthcare organizations that hand off administration to management service organizations are also handing off their exposure.

The stolen data lasts. Diagnoses, prescriptions, and medical histories can't be reissued the way a credit card can. Combined with Social Security numbers, they enable medical identity theft, insurance fraud, and targeted extortion. Hospice and home health patients are mostly elderly or seriously ill, and their families are already stretched, which makes them easier targets for follow-up scams.

The disclosure pattern is typical. The Texas filing gives a precise count, while filings in other states show only single digits. A company operating in eleven states has not published one national total. Defenders and affected people should expect the reported numbers to grow as more state and federal (HHS OCR) filings come in.

Interlock keeps going after healthcare. Interlock is a double-extortion group that has hit healthcare organizations repeatedly. Its leak site works as a pressure tool, and listing a victim usually means negotiations failed or never began.

The Attack Technique

None of the sources say how the attacker got in. AngMar's letter does not describe the entry point. The two-day gap between access and detection (July 18 to July 20) tells us little without knowing when the attacker first got a foothold, since July 18 may mark when data was taken rather than when the intrusion began.

The following is background from earlier public reporting on Interlock, not confirmed for this incident. A joint CISA/FBI advisory published in 2025 and vendor research describe how the group usually operates:

Edelson Lechtzin's claim that the breach started with an employee mistakenly emailing documents does not match AngMar's account, and no other source supports it.

What Organizations Should Do

  1. Audit management service and back-office vendors. List every outside party that holds PHI for your organization. Require proof of EDR coverage, MFA, segmentation, and incident notification deadlines in business associate agreements, and limit vendors to the data they actually need.
  2. Defend against social engineering in the browser. Block fake-update and ClickFix lures: restrict the Run dialog and PowerShell for standard users, filter newly registered and uncategorized domains, and train staff that no real website will ask them to paste commands.
  3. Watch for large outbound transfers. Taking 710 GB requires sustained outbound traffic. Alert on unusual volumes to cloud storage, file-sharing services, and rclone-style tools, especially at night.
  4. Restrict RDP and admin credentials. Remove direct RDP exposure, require MFA for all remote and privileged access, use tiered admin accounts, and watch for new local admin accounts or credential dumping.
  5. Segment and encrypt clinical data stores. Keep EHR exports, billing archives, and file shares holding SSNs and diagnoses off flat networks, and encrypt them at rest so that stolen bulk files are less useful.
  6. Prepare for multi-state notification. Set up a process to produce a single affected count across all states, so that regulators and patients don't have to assemble the scope from separate state filings.

Sources: Texas Hospice Management Company Data Breach Affects ... | PDF AngMar Management Services c/o Cyberscout PO Box 1286 ... | Angmar Management Services Data Breach Lawsuit Investigation | AngMar Management Service Data Breach Investigation | AngMar Management Services Data Breach - Class Action U | AngMar: 35,916 Texans Hit by Major Data Breach | AngMar Management Services Data Breach – Investigated by Federman &... | Edelson Lechtzin LLP Probes Class Action Claims After Customer Data...