Ransomware victim disclosure
← All victimsCoosalud EPS
listed as coosalud.com · Claimed by Threeam · listed 6 hours ago
Status timeline
- ListedSep 28, 2026
- Data leakeddate unknown
At a glance
- Group
- Threeam
- Status
- Data leaked
- Country
- Colombia
- Sector
- Healthcare
- Listed on leak site
- Sep 28, 2026
About the victim
AI dossier — public-source company profileCoosalud EPS (Coosalud Entidad Promotora de Salud S.A.) is a major health promotion entity in Colombia managing subsidized and contributory healthcare regimes. The organization operates with multi-million-peso annual volumes and serves a significant portion of the Colombian healthcare system.
- Industry
- Healthcare – Health Insurance & Promotion Entities (EPS)
Attack summary
Severity: high — Coosalud EPS manages healthcare and insurance data for Colombian citizens across subsidized and contributory regimes. Access to such systems implies potential exposure of personal health information and insurance records at significant scale, characteristic of critical infrastructure in the healthcare/insurance sector. Severity elevated to 'high' pending confirmation of exfiltration vs. encryption-only and actual proof publication.ThreeAM claims to have accessed Coosalud EPS systems. The specific data exfiltrated and operational impact (encryption, data theft, or both) are not detailed in the truncated leak post.
Data the group says was taken
AI dossier — extracted from the leak post- Healthcare records
- Patient information
- Insurance/subscriber data
What the group claims
Coosalud EPS (Coosalud Entidad Promotora de Salud S.A.) is one of the major health promotion entities (EPS) in Colombia, primarily managing subsidized and contributory healthcare regimes with multi-million-peso operating volumes. Alongside its sub
Sources
Source
Indexed 6 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

