Ransomware victim disclosure
← All victimsCS Caritas Socialis
listed as cs.at · Claimed by LockBit · listed 4 months ago
Status timeline
- ListedFeb 14, 2026
- Data leakeddate unknown
At a glance
- Group
- LockBit
- Status
- Data leaked
- Country
- Austria
- Sector
- Technology
- Listed on leak site
- Feb 14, 2026
About the victim
AI dossier — public-source company profileCS Caritas Socialis is an Austrian Catholic charitable organisation based in Vienna that provides a comprehensive range of care and support services. Its offerings include home care, day-centre services for seniors, long-term residential care, specialised dementia and Alzheimer's units, hospice care, multiple sclerosis support, kindergartens, and a mother-and-child shelter. The organisation operates multiple facilities across Vienna and is a recognised model provider in Austria for specialist care.
- Industry
- Healthcare & Social Services (Elderly Care, Hospice & Disability Support)
- Address
- Vienna, Austria
Attack summary
Severity: critical — CS Caritas Socialis handles highly sensitive medical, personal and social-care data for vulnerable individuals including elderly, terminally ill, dementia, MS and domestic-abuse victims. Data has been confirmed published by LockBit, constituting exfiltration of regulated health and personal data (PII) at scale for a healthcare/social-care provider.LockBit claims to have attacked CS Caritas Socialis and has published data (disclosed status: data_published), indicating confirmed exfiltration of organisational data. The exact data categories and volume have not been specified in the post excerpt.
Data the group says was taken
AI dossier — extracted from the leak post- Patient/resident care records
- Personal health information
- Employee records
- Organisational documents
- Financial/donation records
- Contact and location data
What the group claims
CS Pflege & Betreuung Die CS Caritas Socialis bietet Pflege- und Betreuungsangebote aus einer Hand:...
Sources
- Victim sitecs.at
Source
Indexed 4 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

