The INC ransomware group claims to have breached Cabin Creek Health Systems, a West Virginia-based Federally Qualified Health Center that provides medical services to rural and urban communities across Kanawha County.
Cybersecurity monitoring platforms detected the incident on July 23, when INC Ransom added the health center to its dark web leak site. The targeted domain and organizational details were logged by threat intelligence services, marking another healthcare-sector attack by the group.
Cabin Creek Health Systems operates as a nonprofit community health center founded in 1973 by coal miners. It serves patients across multiple West Virginia locations, offering primary care, dental, and behavioral health services to underserved populations. As an FQHC heavily reliant on federal funding, a ransomware incident that disrupts operations or exposes patient data could have severe consequences for its patient base.
The full scope of the breach, including how many patient records may have been accessed or encrypted, remains unclear. No official confirmation or notification has been issued by Cabin Creek Health Systems to regulators or affected individuals at this time.
INC Ransom has a documented history of targeting the healthcare sector. The group previously hit McLaren Health Care, impacting 743,000 patients, and has claimed responsibility for multiple other healthcare attacks. The incident adds to a growing wave of ransomware against healthcare providers in 2026. Research from Comparitech recorded 247 ransomware attacks against healthcare organizations in the first half of the year, with attacks on healthcare businesses rising 35% from the prior period.
Healthcare CISOs should monitor dark web leak sites for patient data exposure and verify vendor incident response protocols. Community health centers with limited IT security budgets are particularly vulnerable to these attacks.
