Skip to content

Lansing Urgent Care network-access incident

Summary

Lansing Urgent Care logo

Lansing Urgent Care shut down its system after detecting an outsider’s attempt to access its network, but did not identify the shutdown’s date, duration or effect on patient care. INC Ransom had listed the provider about 24 hours before the first public account, yet the displayed administrative documents do not prove ransomware, data theft or INC’s responsibility. No continuing clinic or patient-facing disruption was found by August 30, so the incident is presumed resolved operationally while forensic and attribution questions remain open.

Key facts

Timeline

  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Organization types

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

External sources identified the event as cyber-related before the organization publicly confirmed it. The organization publicly documents the resulting service disruption.

Attack mechanisms

  • Unknown cyber mechanism

    The incident is confirmed to be cyber-related, but the specific attack mechanism is unknown.

Data impacts

  • Unknown data impact

    The incident is cyber-related, but available evidence does not establish whether or how data was affected.

Operational impacts

Extortion indicators

  • Leak-site listing

    The victim was listed on a threat actor or ransomware data-leak site as an alleged target or nonpaying victim.

  • Data sample published

    The actor published or shared a sample of allegedly stolen victim data to substantiate the extortion claim.

Incident narrative

Analyst assessment

We reported that Lansing Urgent Care shut down its system after detecting an outsider’s attempt to access its network. The provider said in a written statement distributed through Sabo PR that its controls detected the threat and prevented the attempted access. Internal and technology-provider findings remained preliminary, and Lansing Urgent Care retained a third-party forensic specialist to determine whether protected data was accessed or taken.

INC Ransom listed Lansing Urgent Care at 6:25 p.m. UTC Aug. 17. WILX published the provider’s first public account at 6:45 p.m. UTC Aug. 18, about 24 hours later. The exact victim-name match, close timing and next-day confirmation of malicious activity make the claim likely related to the disclosed incident. They do not, by themselves, prove that INC gained access, deployed ransomware, stole data or caused the shutdown.

The INC listing displays three document images as alleged samples. One is a 2015 safety data sheet for a third-party skin-care product and contains no visible Lansing Urgent Care identifier. The other two are a page from a Lansing Urgent Care business-associate agreement and a page from an apparently incomplete employee nondisclosure agreement. Those documents are administrative, not patient or clinical records. Their appearance on the listing does not authenticate their provenance, establish that they were private or show how INC obtained them.

Operational significance

Lansing Urgent Care said its security response shut down its system, establishing at least a temporary loss of internal system availability. The provider did not identify canceled appointments, closed clinics, delayed patient care, unavailable online check-in or another patient-facing service impact. The operational classification is limited to the documented system shutdown and does not extend to clinical disruption.

The provider operates eight clinics across the Greater Lansing area. Its official online check-in directory lists facilities in Lansing, Okemos, DeWitt, Haslett, Mason and Grand Ledge. The registry locations represent the provider’s network footprint, not a finding that each clinic experienced a separate outage.

Disclosure posture

The INC listing preceded Lansing Urgent Care’s cyber-specific public account, producing an external-first disclosure sequence. The provider’s statements emphasized detection, containment and preliminary findings of no successful access, but did not mention or rebut the already-public INC claim. That creates a material conflict in the public record; it is not evidence of the provider’s motive for framing the event.

The incident is classified XC-OC-OD: an external threat-actor claim appeared Aug. 17, affected-organization cyber wording followed Aug. 18, and the provider disclosed that its defensive response shut down the system. The sequence uses the claim’s publication timestamp, not Ransomware.live’s generated attack-date estimate.

Current status

The incident is presumed resolved operationally. Lansing Urgent Care described the shutdown retrospectively and did not say when it occurred or how long it lasted. No report found by Aug. 30 documented closed clinics, canceled visits, unavailable online check-in or another continuing patient-facing or systems disruption. The forensic investigation may continue, but that does not itself establish continuing service impact.

Aug. 18 remains the last public-observation date for the shutdown, not an established event or restoration date. The absence of a documented patient-facing impact and the lack of later outage reports support presumed resolution, not an affirmative all-clear.

Confidence and uncertainty

Confidence is high that malicious activity and a defensive system shutdown occurred because Lansing Urgent Care described both. Confidence is medium in the presumed-resolved status because no continuing operational impact was found, but the provider did not publish a restoration time. Data impact remains unknown.

The displayed documents are weak evidence of data theft. The third-party safety sheet could have circulated independently of Lansing Urgent Care. The business-associate agreement and nondisclosure agreement are more organization-specific, but neither page contains patient records, clinical data or technical artifacts, and the nondisclosure agreement appears incomplete. INC attribution and ransomware involvement remain assessed with low confidence.

Analytic gaps

The public record does not identify the event date, attempted entry point, targeted account or device, originating infrastructure, authentication outcome, vulnerability, malware, persistence mechanism, shutdown duration or restoration date. It also does not establish which systems or locations were affected or whether any patient-facing workflow was interrupted.

The relationship between the INC listing and Lansing Urgent Care’s event remains unconfirmed. The public record does not establish whether the displayed documents were private, where they originated, when they were obtained, whether INC communicated with the provider or whether later forensic findings support or contradict the provider’s preliminary assessment.

Threat actor and claim

Listed as: Lansing Urgent CareSource: ransomware.livePublished: Discovered:

Claim details

Ransomware.live records an INC Ransom leak-site listing naming Lansing Urgent Care at 6:25 p.m. UTC Aug. 17, 2026. Screenshots attributed to the listing show a 2015 safety data sheet for a third-party skin-care product, one page of a Lansing Urgent Care business-associate agreement and one page of an apparently incomplete employee nondisclosure agreement. The safety sheet contains no visible Lansing Urgent Care identifier, and the other documents are administrative rather than patient or clinical records. The images substantiate that INC displayed material it associated with the provider but do not authenticate the documents, establish that they were private, show how they were obtained or prove access to Lansing Urgent Care’s current network. WILX published the provider’s statement about an outsider’s access attempt and system shutdown about 24 hours after the claim. The timing and exact victim match make the claim likely related, but Lansing Urgent Care has not attributed the event to INC or confirmed ransomware, data theft or encryption.

Screenshot documenting INC Ransom claim

Organizations involved

Impacted locations

Sources

Lansing Urgent Care in Michigan shuts down system after network access attempt

We reported that Lansing Urgent Care shut down its system after detecting an outsider’s network-access attempt. The provider said preliminary findings suggested the attempt was unsuccessful and did not address INC Ransom’s earlier claim or the shutdown’s operational impact.

Lansing Urgent Care INC Ransom claim record

Ransomware.live records a public INC Ransom listing naming Lansing Urgent Care at 6:25 p.m. UTC Aug. 17, 2026. Three screenshots attributed to the listing show a third-party product safety sheet, a business-associate agreement page and an employee nondisclosure agreement page.

Lansing Urgent Care reports attempted cyberattack; no patient data believed leaked

Lansing Urgent Care told WILX that an outsider attempted to access its network. The provider said security controls detected the threat and shut down the system, preventing access. Initial internal and vendor findings suggested the incident was unsuccessful, and a third-party forensic specialist was retained to determine whether protected data was accessed or taken.

Lansing Urgent Care thwarts hack attempt; experts say threat applies to all businesses

WILX reported that Lansing Urgent Care operates eight mid-Michigan locations and was working with specialists and law enforcement to determine the nature and scope of the attempt. The report reiterated that the security system prevented access and that a forensic expert was checking whether data was taken.

Lansing Urgent Care online check-in and clinic locations

The official directory lists eight Lansing Urgent Care clinics: Frandor, Okemos, Westside, Southside, DeWitt, Bath/Haslett, Mason and Grand Ledge. The addresses place the facilities across Ingham, Eaton and Clinton counties in Michigan.

Gazetteer Files

The Census Bureau Gazetteer Files provide authoritative geographic reference data for states, counties, county equivalents and places in the United States.

Lansing Urgent Care official website

The organization’s official website describes its identity, services, operating role and public or customer-facing programs.

See something that needs correction?

Signed-in members can report an error, update, or missing source.