INC Ransom claims attack on Community Wellness Partners

Published September 7, 2026

Ransomware monitoring services report that INC Ransom posted Community Wellness Partners on a leak site. Those reports don't establish whether an intrusion, data theft or system encryption occurred.

Report priority
High
Involves
Community Wellness Partners (attacker claim)
Group
Incransom

What is known

  • The public listing doesn't explain how attackers allegedly gained access or whether they copied data or encrypted systems.
  • Techniques associated with INC Ransom in other attacks don't establish what happened here.

What to do

If you have a relationship with Community Wellness Partners, first check messages and public notices received through channels you already use. Look for a notice that confirms an incident and says whether your information or workplace systems were involved. If the available notices aren't clear, ask the organization's privacy contact, your HR team or your usual business contact for written confirmation about your records or systems. Receiving no notice doesn't prove that you're unaffected.

Follow instructions that Community Wellness Partners provides through a verified notice or a contact route you already trust.

Reported details

Ransomware.live recorded the listing on September 7, 2026 and rendered the group name as “Incransom.” Ransom-DB attributes the post to INC Ransom, which is the name MITRE uses for ransomware and data-extortion group G1032. Neither the general MITRE profile nor the monitoring posts confirm which techniques, if any, were used against Community Wellness Partners. No affected software, CVE, technical entry point or independently confirmed impact is disclosed.