Coös County Family Health
bd_b1954aa65bfd5399 · schema v1 · pii pii-v1
Full breach record for Coös County Family Health →Threat-actor claim — not a regulatory filing
This row is a claim by the ransomware group Runsomewares on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Source: Ransomware.live
Post text · scraped from the leak site
Coös County Family Health Services has provided comprehensive office-based primary care services for more than 10 years.
J jump to incidentP pin to compareR raw source
Incident timeline — mostly unverified
? — ?
Breach window unknown
Jul 10, 2025
Claim posted
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Claim → filing
—
Compliance clock
Not assessable
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- HHS OCRbd_8f8dbcd50604b6cb2025-09-05 · +57dCandidate
- Illinois State AGbd_6092bef5a34d0ff62025-10-01 · +83dVerified by operator
- Vermont State AGbd_4157a034d7aa6a462025-10-09 · +91dVerified by operator
- Maine State AGbd_baf9b9fa162a0aaa2025-10-09 · +91dVerified by operator
Show 2 more filings ↓Show fewer ↑up to 91d gap
- Massachusetts State AGbd_bba4837ae5e628e12025-10-09 · +91dVerified by operator
- New Hampshire State AGbd_f14806bbae507beb2025-10-09 · +91dVerified by operator
Filing propagation · 7 filings · 5 states
View merged incident ↗Pattern: first filing Jul 10, last Oct 9 (NH) — a 91-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
Source ceiling
- actor name
- victim claim
- ransom/leak status
- discovery date
- materiality
- notification
- affected count
- confirmed data types
- compliance clock
The ✕ fields stay blank until a regulatory filing or victim disclosure lands.
runsomewares
According to ransomware.live, RunSomeWares is an emerging ransomware group that surfaced in February 2025 with initial victims across supply-chain services, financial services, accounting, and manufacturing, with unclear deployment of an encryptor vs. pure data-theft extortion.