Group:
Incransom
Discovered by ransomware.live: 2025-07-31
Estimated attack date:
2025-05-15
Country:
Description:
The West Virginia Primary Care Association (WVPCA) is dedicated to providing accessible and affordable healthcare services throughout West Virginia. They support over 550 Community Health Centers that offer a wide range of medical services including primary care, dental, and mental health services. Aiming to serve the healthcare needs of West Virginians, WVPCA focuses on patient-centered care and community health initiatives. With a commitment to advocacy and quality improvement, their vision is to enhance healthcare delivery in rural areas.
Employees: 25
Revenue:$5 Million
Industry:Hospitals
Phone Number:(304) 346-0032
Sherri Ferrell (President & Chief Executive Officer) Cell (304) 542-6114
Debra Boyd (Chief Financial Officer/Chief Operations Officer) Cell (304) 552-4477
Matthew Arthur (Communications Coordinator) Cell (304) 415-0024
Carolyn Canini (Director of School Based/Behavioral Health Services ) Cell (304) 550-1435
Megan Diehl (Communications Director) Cell (304) 549-1147
Jessica Haas (Director of Clinical Transformation) Cell (304) 544-4281
Aaron Johnson (Special Projects Director) Cell (304) 444-8602
Jessica Keathley (Health Data Analyst) Cell (304) 972-7793
Scot Mitchell (Director of Value Based & Managed Care Services) Cell (970) 640-5171
Shannon Parker (Director of Health Center Operations) Cell (304) 661-5741
Ruby Piscopo (Outreach & Enrollment Coordinator) Cell (304) 561-8195
Amanda West (Finance & Operations Manager) Cell (304) 639-2273
DNS Records:
The following DNS records were found for the victim's domain.
- domain.operations@web.com
- wvpca-org.mail.protection.outlook.com.
- v=spf1 include:spf.protection.outlook.com -all
- MS=ms89252540
- google-site-verification=jeteGWmoD2syvDBlk8n9POWEMiJY-vxu-es7InZPTBA
- sophos-domain-verification=b7470b4b04eba473bc955e42ee80d656e5ec34d1e91d5c71ebbdf8e95df013cc
Cloud / SaaS Services Detected
Microsoft 365
Sophos
Leak Screenshot:
Legal Disclaimer:
Ransomware.live does not engage in the acquisition, exfiltration, downloading, possession,
hosting, access, consultation, redistribution, or disclosure of unlawfully obtained data.
This platform indexes only publicly visible information posted by ransomware operators and
open web sources without accessing or obtaining the underlying stolen content.
The service is provided to support public awareness, legitimate research, and cyber-resilience.
No stolen personal or confidential data is collected or distributed via this site.