LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Avamere Family of Companies Listed by avoslocker Ransomware Group

HIGH severityUnverified claimHow we verify

Avamere Family of Companies Listed by avoslocker Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·December 26, 2022
Avamere Family of Companies Listed by avoslocker Ransomware Group

Reported December 26, 2022.

HIGH
Severity
December 26, 2022
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The Avamere Family of Companies Listed by avoslocker Ransomware Group (reported December 26, 2022) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

In late December 2022, the Avamere Family of Companies appeared on a listing associated with the AvosLocker ransomware group. Public detail is limited: the number of people affected remains unknown, and the only description of what was taken is that internal files were allegedly exfiltrated in a ransomware attack. For patients, residents, employees, and others whose information may sit inside those systems, the practical stake is straightforward. Healthcare organizations hold records that can be used for identity misuse, insurance fraud, or targeted scams long after an incident is first reported.

What is confirmed in available reporting is modest. Avamere was listed by AvosLocker; the report date is December 26, 2022; and the material described is internal files removed during a ransomware incident. Everything beyond that—exact timing of intrusion, full scope, and precise contents—has not been publicly detailed in the facts at hand. That uncertainty is itself part of the picture for anyone trying to judge personal risk.

Breaking down the breach

According to the available record, Avamere Family of Companies was listed by the AvosLocker ransomware group on or about December 26, 2022. The report states that internal files were exfiltrated in a ransomware attack. No figure is given for the number of individuals affected. No technical description of the initial access method, dwell time, encryption status of systems, or ransom demand appears in the facts provided. Public detail on those points is therefore limited.

Ransomware incidents of this type commonly involve both encryption of systems and theft of data before encryption, a pattern often called double extortion. The listing itself is a claim by the group that it holds or has taken material from the organization. Independent confirmation of the full extent of any compromise is not supplied in the source facts. Readers should treat the leak-site appearance as an unverified assertion by the threat actor unless and until the organization or regulators publish fuller findings.

Who is avoslocker?

AvosLocker is a ransomware operation that became widely known in the cybersecurity community around 2021. Like many contemporaneous groups, it has been associated with double-extortion tactics: encrypting victim systems while also copying data and threatening to publish it if payment is not made. The group has historically used leak sites to name organizations and, in some cases, to release samples or larger sets of stolen files. It has targeted a range of sectors, including healthcare and other service industries, though specific victim lists change over time.

Public reporting has described AvosLocker as operating with affiliates in a model sometimes labeled ransomware-as-a-service, though the precise internal structure of any criminal group is difficult to verify from outside. Typical tactics attributed to the broader ecosystem include phishing, exploitation of remote-access services, and lateral movement once inside a network. None of that general background proves the exact pathway used against Avamere; it only situates the name that appeared on the listing. Claims made on a ransomware leak site about any particular victim—including what was taken and whether systems remain encrypted—should be read as the group’s assertions, not as independently audited fact.

About Avamere Family of Companies

Avamere Family of Companies was founded in 1995 and is headquartered in Wilsonville, Oregon. It is described as a group of healthcare organizations and systems. Organizations of this kind typically operate or manage skilled nursing, rehabilitation, senior living, or related care services. They sit at the intersection of clinical care, billing, insurance, and employment records.

A breach involving a multi-entity healthcare group is consequential because the same corporate umbrella may touch many facilities, vendors, and individuals. Even when public reporting does not name every subsidiary or site, the concentration of sensitive operational and personal data makes such organizations attractive targets and raises the potential impact if internal files leave the environment. The facts do not establish negligence or describe defensive posture; they simply place a known healthcare operator on a ransomware group’s list.

What data was at risk

The facts state that internal files were exfiltrated in a ransomware attack. No further breakdown—such as whether the files included medical records, billing data, employee information, or operational documents—is provided. The number of people affected is unknown.

Healthcare organizations of Avamere’s type commonly hold protected health information, insurance and payment details, contact data, and employment or contractor records, along with internal business documents. That is the ordinary profile of the sector, not a confirmed inventory of what left Avamere’s systems. Because the exact contents remain undisclosed in the available record, it is not possible to state with certainty which categories of personal data, if any, were included in the exfiltrated files. Anyone who has been a patient, resident, employee, or business partner should treat exposure as possible rather than proven until more specific notice is issued.

What's at stake

For individuals, the concrete risks of healthcare-related file theft include identity theft, fraudulent use of insurance information, and social-engineering attempts that reference real care details or account numbers. Stolen internal documents can also help criminals craft more convincing phishing messages. These harms may surface months later, which is why monitoring and caution remain useful even when an organization has not published a full list of affected people.

For the organization, a ransomware incident can disrupt care operations, force costly recovery work, trigger regulatory notification duties, and damage trust with patients and partners. The facts do not quantify financial loss, downtime, or regulatory outcomes for this case. The listing alone does not prove the full operational impact; it does indicate that a known ransomware actor claimed to have taken internal material and sought leverage from that claim.

What to do if you're exposed

If you have a relationship with Avamere Family of Companies—as a patient, resident, family member, employee, or contractor—watch for official notices from the organization or from regulators. Consider placing a fraud alert or credit freeze with the major credit bureaus if you believe sensitive identifiers may have been involved, and review insurance explanations of benefits for unfamiliar claims. Be skeptical of unexpected calls or messages that reference your care or personal details; verify through known official channels rather than links or numbers supplied in the message.

Keep records of any correspondence about the incident. Where available, use identity-monitoring or credit-monitoring offers if they are extended. As a practical additional step, you can run a free exposure scan of your email address to check whether your information has already surfaced in known breach data sets, which may help you decide how closely to watch accounts and credit files going forward.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyAvamere Family of Companies security record
88/100
DoxxScan™ · Low doxx risk
B 83Good record

1 reported incident on record.

See Avamere Family of Companies’s full breach history →

More recent breaches

Zeus Scientific Inc Listed by avoslocker Ransomware GroupDecember 26, 2022McKenzie Health System Listed by avoslocker Ransomware GroupDecember 26, 2022CMHA National Listed by avoslocker Ransomware GroupDecember 26, 2022CHRISTUS Health Listed by avoslocker Ransomware GroupDecember 26, 2022

Latest breaches

Read GalaxyWarden’s full analysis of the Avamere Family of Companies Listed by avoslocker Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by avoslocker — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram