Integris Health, an Oklahoma not-for-profit health network, announced on 24 December 2023 that it had found suspicious activity in its systems. Reporting places the intrusion at 28 November 2023 and the company later confirmed the breach affected approximately 2.4 million patients.
Between 24 and 27 December, patients began receiving emails from people claiming responsibility. The messages set a deadline of 5 January 2024 and offered, via a dark web site, $3 to view a stolen record and $50 to have it deleted.
The Extortion Was Retailed
This is the only file in this database where the extortion was addressed to the data subjects rather than to the organisation. The pressure did not run through the hospital at all.
Every mechanism the corpus records for handling extortion assumes a corporate counterparty: a board deciding whether to pay, insurers, counsel, law enforcement liaison. A patient receiving an individual demand for $50 has none of that, and no basis whatsoever to believe deletion would follow payment.
The Number In The Email Is Not The Number
Reporting describes the data being listed as covering roughly 4.67 million people. Integris confirmed approximately 2.4 million.
The desk records the confirmed figure and treats the larger one as a claim, for the reasons set out at 24-1001 and 23-0923. A number chosen by someone trying to frighten people is a marketing figure.
A Notification Regime With No Answer For This
Breach notification exists so that an organisation tells affected people what happened. Here the attackers told them first, with a deadline and a price, before the organisation had finished establishing scope.
The corpus argues at 25-1031 that the standard remedies — credit monitoring, settlement funds — are poorly matched to the harm. This file is worse than that: the remedy machinery had not started when the harm was already being monetised patient by patient.
Built on contemporaneous reporting of Integris Health’s announcement and of the extortion emails patients received, and on later reporting of the confirmed victim count. The 24 December announcement, the approximately 2.4 million confirmed figure and the data categories are the organisation’s as reported. The 28 November intrusion date, the content of the extortion emails, the $3 and $50 amounts and the 5 January deadline are from reporting; this desk has not seen the emails. The larger figure of roughly 4.67 million originates with the people claiming responsibility and is not carried in the record. No dark web address is reproduced. Graded high. Corrections: corrections@forensicpost.com.