Ransomware victim disclosure
← All victimseCare Platform
Claimed by CRPxO · listed 3 days ago
Status timeline
- ListedJul 27, 2026
- Data leakeddate unknown
At a glance
- Group
- CRPxO
- Status
- Data leaked
- Country
- United States
- Sector
- Healthcare
- Listed on leak site
- Jul 27, 2026
About the victim
AI dossier — public-source company profileeCare Platform is a healthcare technology company that provides customizable, branded mobile applications for clinical research and patient monitoring. They specialize in real-time symptom tracking, data collection, and physician collaboration tools, with a focus on dermatological research (eczema, psoriasis tracking) and chronic disease management. The platform serves healthcare providers, research institutions, and pharmaceutical companies.
- Industry
- Healthcare Technology & Clinical Research Software
Attack summary
Severity: critical — Healthcare sector with confirmed exfiltration of 14.2 GB and published data. The platform processes patient health records, symptom data, and clinical research information (likely including PII and protected health information under HIPAA). Large-scale exfiltration of medical data from a clinical research platform constitutes critical severity.CRPxO claims to have exfiltrated 14.2 GB of data from eCare Platform. The group has published the data; no ransom demand is stated.
Data the group says was taken
AI dossier — extracted from the leak post- patient medical records
- symptom tracking data
- clinical research data
- user health information
- study participant data
- application source code or configuration
What the group claims
Sector: Healthcare / Technology | Data leaked: 14.2 GB
Sources
Source
Indexed 3 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

