RiverSoft Listed by ransomhouse Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The RiverSoft Listed by ransomhouse Ransomware Group (reported June 30, 2024) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
Ransomware groups continue to target software providers that sit at the centre of specialised industries, using data theft and public leak-site listings as leverage. In late June 2024 one such listing named RiverSoft, a long-established home-care software vendor, as a victim of the group known as ransomhouse. Public detail remains limited, yet the claim alone raises clear questions for agencies that rely on the platform and for the patients and staff whose information may have been involved.
What is known is that RiverSoft appeared on the group’s leak site with a report date of 30 June 2024. The listing asserts that internal files were exfiltrated during a ransomware attack. No confirmed figure for the number of people affected has been released, and the precise method of intrusion has not been disclosed by either the company or independent investigators.
What happened
On 30 June 2024 the ransomware group ransomhouse listed RiverSoft on its public leak site. The group claims that internal files were taken in a ransomware attack. Beyond that assertion, key facts remain undisclosed: the scale of the intrusion, the exact date the attackers first gained access, the volume of data removed, and whether any ransom demand was paid or refused. No independent confirmation of the breach has been published, so the listing stands as an unverified claim by the threat actor. Organisations in this position typically face pressure to negotiate or to prepare for possible data publication, but no further statements from RiverSoft itself appear in the available record.
Inside ransomhouse
Ransomhouse is a ransomware operation that follows the now-common double-extortion model. The group typically gains access to a network, steals data, encrypts systems, and then threatens to publish the stolen material on a dedicated leak site if payment is not made. Like many contemporary ransomware crews, it maintains a public-facing portal where it posts victim names, sample files, and countdown timers. Prior activity attributed to the group has included listings of mid-sized enterprises and service providers across several sectors; the pattern is consistent with opportunistic targeting of organisations that hold operationally valuable or regulated data. In the present case the group claims RiverSoft’s internal files were exfiltrated, but no additional technical details or sample data specific to this victim have been independently verified.
Who is RiverSoft?
RiverSoft develops software for home-care agencies. According to its own description, the product is the result of more than twenty years of design work and is built for large agencies that manage thousands of patients across multiple locations. It handles varied and changing payer requirements, including Medicare, Medicare Advantage, Medicaid, commercial insurance, HMOs and self-pay arrangements. The platform is optimised for high-volume employee and patient populations, presenting all relevant information on a single screen to reduce administrative time. In short, RiverSoft sits inside the clinical and billing workflows of home-health providers. A breach at such a vendor is consequential because the software routinely processes protected health information, employee records and financial data that agencies must keep confidential under healthcare privacy rules.
What was likely exposed
The only data type named in the public listing is “internal files exfiltrated in a ransomware attack.” No further inventory—such as patient charts, billing records, employee credentials or source code—has been confirmed. Organisations of this kind typically store electronic health records, care plans, insurance identifiers, staff contact details and system configuration files. Because the exact contents remain unconfirmed, it is not possible to state which of those categories, if any, were taken. Readers should treat any more specific claims as speculative until RiverSoft or a regulator provides an official accounting.
The real-world impact
For individuals whose data may have been involved, the primary risks are identity theft, medical fraud and unwanted contact. Stolen health or insurance information can be used to open fraudulent accounts or to submit false claims. Employees face the additional possibility that payroll or authentication details could be misused. For RiverSoft and its customer agencies the consequences include potential regulatory scrutiny, notification costs, temporary disruption of care-coordination systems, and the longer-term task of restoring trust. Because the number of people affected is still listed as unknown, the full scope of these risks cannot yet be quantified. Even so, any organisation that relies on the software should treat the listing as a signal to review access logs, rotate credentials and prepare for possible patient or staff inquiries.
Were you affected?
If you work for a home-care agency that uses RiverSoft, or if you or a family member receive care through such an agency, treat the situation as a possible exposure until official notices arrive. Monitor financial and insurance statements for unexpected activity, place a fraud alert with the major credit bureaus if you suspect misuse, and change passwords on any accounts that may have shared credentials with work systems. You can also run a free exposure scan of your email address to check whether it has already appeared in known breach data sets. Keep records of any official communications from RiverSoft or your care provider, and follow their guidance once it is issued. Public information remains limited, so measured caution is the most practical response for now.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Lake Washington Institute of Technology Listed by ransomhouse Ransomware GroupCreative Realities Listed by ransomhouse Ransomware GroupTrellix (McAfee & FireEye) Listed by ransomhouse Ransomware GroupUnitedLayer Listed by ransomhouse Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the RiverSoft Listed by ransomhouse Ransomware Group →
Publicly posted by ransomhouse — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.