How an International Syndicate Gamed Oklahoma’s Medicaid System
Inside Attorney General Gentner Drummond’s blockbuster investigation into the state’s managed care rollout, foreign botnets, and an administration looking the other way.
When an ordinary envelope from SoonerCare arrives in your mailbox, you expect a routine notice—a prescription update, a quarterly breakdown, or a reminder about an upcoming dental checkup.
You do not expect to open it and find an active, fully assigned Medicaid managed care enrollment packet issued under your name—complete with a assigned primary care physician—when you never applied for benefits in the first place.
Across Oklahoma, thousands of residents have opened their mail over the past year to find precisely that.
What seemed at first like a bizarre administrative glitch inside the state's newly overhauled Medicaid system has morphed into one of the largest public corruption and national-security-adjacent scandals in state history. In mid-July, Oklahoma Attorney General Gentner Drummond announced a formal criminal investigation into the Oklahoma Health Care Authority (OHCA). The charge? Allowing an international criminal syndicate to infiltrate the state's open enrollment portal, generate thousands of fraudulent Medicaid accounts, and extract public healthcare funding while state administrators quietly buried the alarm bells.
For a state already weary of agency scandals, the revelation feels like a fever dream. But to understand how overseas hackers allegedly transformed Oklahoma's safety net into an automated ATM, you have to look at the intersection of political ideology, privatization, and a state bureaucracy designed to keep law enforcement in the dark.
The Phantom Enrollees
The mechanics of the breach are a masterclass in modern automated fraud.
During the state's open enrollment period, an international criminal ring deployed digital botnets using leaked personal identifiable information (PII) to systematically pass through OHCA’s online eligibility process. The algorithms bypassed verification hurdles, creating thousands of "ghost" enrollees.
Once inside SoonerCare, these fake enrollees were automatically routed into the state's newly privatized managed care program—a system known as SoonerSelect, administered by out-of-state insurance giants like Aetna, Humana, and Oklahoma Complete Health.
Under managed care contracts, private insurance companies receive a fixed per-member, per-month payment (a "capitation rate") from state tax dollars to manage each enrollee’s health, regardless of whether that patient actually seeks medical treatment.
For legitimate patients, this structure is supposed to incentivize preventative care. For an international criminal syndicate manipulating thousands of ghost accounts, it is free money.
The Bottleneck by Design
In a functioning government, an influx of phantom enrollees triggering thousands of bounced mail notices and identity theft complaints would immediately summon the state’s law enforcement arm: the Attorney General’s Medicaid Fraud Control Unit (MFCU).
Except in Oklahoma, the door between the agency and the prosecutors had been deliberately locked.
Under federal regulations, states have a choice in how managed care entities report suspected fraud. They can mandate that insurers report directly to the Attorney General’s criminal investigators, or they can route complaints through the state’s Medicaid agency—in this case, the Governor Kevin Stitt-appointed leadership at the OHCA.
Stitt’s administration chose the latter.
The result was a total breakdown in oversight:
- In Fiscal Year 2025, private insurance entities flagged 168 potential fraud schemes to the OHCA.
- OHCA leadership passed along exactly two of those 168 referrals to Attorney General Drummond's office.
- Between 2022 and 2024, out of 509 fraud investigations handled by the Attorney General, only 11 originated from the OHCA.
"When my office is not notified in a timely manner that thousands of fraudulent accounts were opened inside our state's Medicaid program by foreign actors, that's not a paperwork failure," Drummond declared when announcing the probe. "It's a breakdown in OHCA administration."
Total Managed Care Fraud Warnings (FY25): [168] ----------------------
Referrals OHCA Sent to Prosecutors: [ 2] -
The Broader Civil War in Oklahoma Politics
While the spectacle of offshore cyber-criminals raiding SoonerCare makes for national headlines, inside the state Capitol, the scandal is the latest battleground in an ongoing political war between Attorney General Drummond and Governor Stitt.
Drummond, a pragmatic Republican who has positioned himself as an aggressive watchdog against corruption in state government, warned OHCA leadership for months about systemic flaws. In March, Drummond sent formal correspondence demanding answers regarding payment delays to rural clinics and uninvestigated fraudulent claims. OHCA’s formal response weeks later cited statistics defending their insurance vendors while entirely dodging questions on foreign fraud rings.
By April, Drummond requested a full audit of the agency from State Auditor Cindy Byrd. By July, the audit request turned into a full-scale criminal investigation.
For rural health centers and pediatric care clinics across Eastern Oklahoma—many of which have faced crippling payment delays under the new managed care framework—the corruption scheme lands as a bitter pill. Local doctors have spent months fighting bureaucratic red tape to get reimbursed for treating real children, while millions in taxpayer funds quietly drifted out the back door to ghost profiles.
What Happens Next?
The Attorney General’s office has launched an online Medicaid Enrollment Fraud Report portal, urging any Oklahoman who received an unsolicited SoonerCare packet to submit a report. Submissions are helping investigators map out the full physical footprint of the identity theft network across all 77 counties.
As grand jury subpoenas roll out and state auditors comb through server logs at the OHCA, the question for Eastern Oklahomans is no longer if state safety-net programs were exploited, but who inside state leadership decided to look away while it happened.
For more context on local enforcement actions targeting billing irregularities and healthcare fraud in the region, check out this local report covering Medicaid fraud enforcement cases in Oklahoma. It offers helpful background on how state and federal authorities investigate improper provider billing and identity theft across SoonerCare programs.