A Texas-based home care management company has just disclosed a data breach of deeply concerning proportions. Highly sensitive medical and personal information may now be in the hands of cybercriminals.
Behind the attack stands a name well known in ransomware circles: Interlock, a group claiming to have exfiltrated 710 gigabytes of confidential data. This incident is yet another stark reminder of how vulnerable healthcare infrastructure remains in the face of sophisticated cyberattacks.
Here is everything we know about the incident, the data that has been compromised, and the real risks facing those affected.
AngMar Management Services: A Breach Detected Too Late

AngMar Management Services, headquartered in Mansfield, Texas, operates home care and palliative hospice facilities across 11 U.S. states. Founded in 2000, the company works in a particularly sensitive sector where patient data ranks among the most valuable — and most targeted — assets for cybercriminals.
According to a filing with the Texas Attorney General, an unauthorized actor gained access to the company’s systems on or around July 18, 2026. It was not until July 20 that AngMar detected unusual activity, triggering a forensic investigation. A two-day window that, in cybersecurity terms, is more than enough time to exfiltrate substantial volumes of data.
The number of individuals officially affected in Texas stands at 35,916 residents, according to an analysis of the regulatory filing by Claim Depot. That figure covers Texas alone — the full national scope of the incident remains unclear, given AngMar’s presence across ten additional states.
Highly Sensitive Medical and Personal Data Compromised
The nature of the information potentially exposed is particularly alarming. Beyond standard identification data, it appears that complete medical records may have been compromised:
- Personal data: names, addresses, dates of birth, Social Security numbers
- Medical data: patient identifiers, medical record numbers, health insurance information, dates of care, diagnoses, provider names, prescription details, and medical histories
This type of data is a goldmine for cybercriminals. On dark web marketplaces, a complete medical record commands far higher prices than a simple credit card number — it enables insurance fraud, medical identity theft, and even targeted extortion.
On August 11, 2026, the Interlock ransomware group publicly claimed responsibility for the attack on the dark web, asserting they hold 710GB of data belonging to AngMar. Notably, the official notification letter sent by the company to those affected makes no mention of this claim. AngMar simply states that there is “no evidence that the information has been or will be misused.”
Interlock: A Ransomware Group to Watch Closely
Interlock is no unknown player in the cyberthreat landscape. Active since 2024, the group primarily targets the healthcare, critical infrastructure, and public sector industries — sectors known for their willingness to pay ransoms in order to protect sensitive data.
The claim of 710GB of exfiltrated data places this attack among the most significant incidents of the year. For context, 710GB can hold millions of structured patient files. Should this data be published or resold, the consequences for victims could unfold over years.
In response to the incident, AngMar is offering affected individuals complimentary credit monitoring covering one bureau, a credit report, and a credit score through the Cyberscout platform. This is a standard measure in situations like this, but it does not address the risks tied to the exposure of medical data — a significant blind spot in the company’s current response.