Desk live·
ForensicPost
Ransomware/Healthcare/File 23-1224

Integris Health Patients Were Emailed Directly and Offered a $50 Deletion Fee

Rather than pressuring the hospital system, the operators went to the patients — emailing them individually with a deadline, $3 to view their own stolen record and $50 to have it deleted. The extortion was retailed to the people the data described.

Constructed geometry · not a chart of case data
JurisdictionUSAthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetIntegris Health
ActorUnattributed
S. Rosler11 min readConfidence: high2 sources reviewed

Integris Health, an Oklahoma not-for-profit health network, announced on 24 December 2023 that it had found suspicious activity in its systems. Reporting places the intrusion at 28 November 2023 and the company later confirmed the breach affected approximately 2.4 million patients.

Between 24 and 27 December, patients began receiving emails from people claiming responsibility. The messages set a deadline of 5 January 2024 and offered, via a dark web site, $3 to view a stolen record and $50 to have it deleted.

The Extortion Was Retailed

This is the only file in this database where the extortion was addressed to the data subjects rather than to the organisation. The pressure did not run through the hospital at all.

Every mechanism the corpus records for handling extortion assumes a corporate counterparty: a board deciding whether to pay, insurers, counsel, law enforcement liaison. A patient receiving an individual demand for $50 has none of that, and no basis whatsoever to believe deletion would follow payment.

The Number In The Email Is Not The Number

Reporting describes the data being listed as covering roughly 4.67 million people. Integris confirmed approximately 2.4 million.

The desk records the confirmed figure and treats the larger one as a claim, for the reasons set out at 24-1001 and 23-0923. A number chosen by someone trying to frighten people is a marketing figure.

A Notification Regime With No Answer For This

Breach notification exists so that an organisation tells affected people what happened. Here the attackers told them first, with a deadline and a price, before the organisation had finished establishing scope.

The corpus argues at 25-1031 that the standard remedies — credit monitoring, settlement funds — are poorly matched to the harm. This file is worse than that: the remedy machinery had not started when the harm was already being monetised patient by patient.

How we reported this

Built on contemporaneous reporting of Integris Health’s announcement and of the extortion emails patients received, and on later reporting of the confirmed victim count. The 24 December announcement, the approximately 2.4 million confirmed figure and the data categories are the organisation’s as reported. The 28 November intrusion date, the content of the extortion emails, the $3 and $50 amounts and the 5 January deadline are from reporting; this desk has not seen the emails. The larger figure of roughly 4.67 million originates with the people claiming responsibility and is not carried in the record. No dark web address is reproduced. Graded high. Corrections: corrections@forensicpost.com.

Sources
  1. Integris Health says data breach impacts 2.4 million patientsBleepingComputer
  2. $30 Million Settlement Agreed to Resolve Integris Health Class Action Data Breach LawsuitHIPAA Journal
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary