LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Liberty Healthcare Corporation Listed by Storm Ransomware Group

HIGH severityUnverified claimHow we verify

Liberty Healthcare Corporation Listed by Storm Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·August 6, 2026

SourceLeak-site claim data adapted from RansomLook.io, used under CC BY 4.0.

Liberty Healthcare Corporation Listed by Storm Ransomware Group

Reported August 6, 2026.

HIGH
Severity
August 6, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Liberty Healthcare Corporation was listed by the Storm ransomware group on 6 August 2026 after internal files were exfiltrated in a ransomware attack; the number of individuals affected has not been disclosed. Anyone who has received services from Liberty Healthcare should verify their personal information and monitor accounts for unusual activity.

Severity & verification
HIGH severityUnverified claim
Contact / identity PII exposed.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Was your email in the Liberty Healthcare Corporation Listed by Storm Ransomware Group breach?
See every leak tied to your email — not just this one. 15-second check, no card, no account. Details go to your inbox.

People who receive care through Liberty Healthcare Corporation, or who work with the organization, may be wondering whether their personal information was caught up in a recent ransomware incident. Public reporting indicates that the company has been listed by the Storm ransomware group, which claims to have taken internal files. The number of people affected remains unknown, and many operational details have not been released, leaving those connected to the organization with limited clarity about what, if anything, was exposed.

For individuals who rely on health and human services providers, even an unconfirmed listing raises practical concerns about privacy, identity, and the security of sensitive records. What is known so far is narrow; what matters is understanding the claim, the actor behind it, and the steps people can reasonably take while official information stays incomplete.

Breaking down the breach

According to available reporting dated August 06, 2026, Liberty Healthcare Corporation was listed by the Storm ransomware group. The group’s claim centers on the exfiltration of internal files in a ransomware attack. No confirmed figure has been published for the number of people affected. Specifics about how the incident began, when systems were first accessed, how long any intrusion lasted, or what volume of data was involved have not been disclosed in the public record summarized here.

Ransomware incidents typically involve unauthorized access followed by encryption of systems and, in many cases, theft of data before encryption. In this instance, the public description states that internal files were exfiltrated. Beyond that characterization, timing, scale, and technical method remain undisclosed. The listing itself should be treated as a claim by the group rather than an independently verified accounting of every detail.

The group behind it: Storm

Storm is a ransomware operation known in public cybersecurity reporting for double-extortion tactics: encrypting victim systems while also copying data and threatening to publish or sell it if demands are not met. Groups operating under this model commonly maintain leak sites where they name organizations and, at times, release samples or larger sets of stolen files to increase pressure. Their tooling and affiliate structures have varied over time, but the core pattern—initial access, lateral movement, data theft, and extortion—is well documented across multiple incidents attributed to actors using the Storm name or closely associated brands.

With respect to Liberty Healthcare Corporation, the available facts state only that the organization was listed and that internal files were described as exfiltrated. No further statements from the group about this specific victim—such as ransom amounts, deadlines, or sample file descriptions—are included in the provided record. Any broader claims circulating outside that record should be treated cautiously until corroborated by the organization or independent investigators.

Who is Liberty Healthcare Corporation?

Liberty Healthcare Corporation is described as a health and human services management company with more than three decades of work addressing complex healthcare challenges. Its focus areas include health workforce outsourcing, program management, and population health management, with particular attention to specialized and vulnerable populations. Public descriptions of its work reference expertise in behavioral health, aging, and intellectual and developmental disabilities, and an emphasis on person-centered approaches intended to improve quality and performance in healthcare settings.

Organizations in this sector routinely handle clinical, administrative, and operational information tied to people who may already face heightened privacy and safety risks. A breach claim involving such a provider is consequential because the data environment often includes records that, if misused, can affect care continuity, benefits, housing stability, or personal safety—not only financial accounts. The company’s role supporting vulnerable populations makes careful handling of any incident especially important, regardless of whether every claimed detail is later confirmed.

The information in question

The facts name the exposed material as internal files exfiltrated in a ransomware attack. No further breakdown—such as whether the files included medical records, employee data, billing information, program participant lists, or only administrative documents—has been disclosed in the material provided. Exact contents therefore remain unconfirmed.

Health and human services management organizations typically hold a mix of data: identifiers and contact details, clinical or case-management notes, insurance and billing records, workforce and contractor information, and operational documents related to programs for behavioral health, aging, or disability services. That is the general profile of the sector, not a verified inventory of what Storm claims to hold in this case. Until Liberty Healthcare Corporation or regulators publish a more precise accounting, it is not possible to state which categories were actually taken.

The real-world impact

For individuals, the primary risks in incidents of this type include identity theft, targeted phishing that references real program or employment details, and potential misuse of health-related or disability-related information. Even when medical charts are not confirmed as exposed, internal files can still contain enough personal context to make social-engineering attempts more convincing. People connected to specialized populations may face additional stress if they fear stigma or interference with services.

For the organization, consequences can include operational disruption, regulatory notification duties, contractual obligations to partners and government programs, and the cost of investigation and remediation. Reputation and trust with clients, families, and referring agencies may also be affected. Because the number of people affected is unknown and the precise data types are not fully detailed publicly, the full scope of impact cannot yet be measured from open sources alone.

If your data was in this breach

If you receive services through Liberty Healthcare Corporation, work for the organization, or otherwise believe your information may have been involved, begin with basic precautions. Monitor financial and insurance statements for unfamiliar activity. Be skeptical of unexpected calls, emails, or messages that reference your care, benefits, or employment and press you for credentials or payments. Consider placing a fraud alert with major credit bureaus if you have reason to think identifiers such as Social Security numbers could have been included, and keep records of any official notices you receive from the company.

You can also run a free exposure scan of your email address to check whether your information has already surfaced in known breach datasets. That step does not confirm or rule out involvement in this specific incident, but it can help you see whether your address appears in other publicly tracked leaks and decide whether further monitoring is warranted while waiting for clearer official updates.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyLiberty Healthcare Corporation security record
64/100
DoxxScan™ · Moderate doxx risk
B- 76Above-average record

1 reported incident on record.

See Liberty Healthcare Corporation’s full breach history →

More recent breaches

OVP Health Listed by Storm Ransomware GroupAugust 6, 2026Southern Indiana Radiological Associates Listed by Storm Ransomware GroupAugust 6, 2026Pioneer Bank Listed by Storm Ransomware GroupAugust 6, 2026Nelson Manufacturing Listed by Storm Ransomware GroupAugust 6, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the Liberty Healthcare Corporation Listed by Storm Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by storm — unverified claim, pending independent verification. Leak-site claim data adapted from RansomLook.io, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram