Ransomware victim disclosure
← All victimsEva Care
Claimed by Thegentlemen · listed 16 days ago
Status timeline
- ListedAug 10, 2026
- Data leakeddate unknown
At a glance
- Group
- Thegentlemen
- Status
- Data leaked
- Country
- United Kingdom
- Sector
- Healthcare
- Listed on leak site
- Aug 10, 2026
About the victim
AI dossier — public-source company profileEva Care Group is a healthcare provider headquartered in Los Angeles, California, specializing in post-acute care with over 50 years of combined experience. The company operates and manages a network of nursing homes and rehabilitation facilities, delivering clinical, financial, operational, and environmental management services.
- Industry
- Healthcare: Post-Acute Care, Nursing Homes & Rehabilitation Facilities
- Address
- Los Angeles, California, USA
- Employees
- 51-200
Attack summary
Severity: medium — Data published status confirmed with operational access demonstrated, but no proof files, data categories, or scale specified. Healthcare sector elevates concern due to potential PII/medical data exposure, but lack of concrete disclosure details prevents higher rating.thegentlemen claims to have compromised Eva Care Group and published data. The post does not explicitly state whether data was exfiltrated, encrypted, or both, nor specify what data categories are at stake.
What the group claims
evacare.com rocketreach.co/eva-care-profile_b7a227f8c53b4785 Eva Care Group is a healthcare provider specializing in the post-acute care industry, headquartered in Los Angeles, California. With over 50 years of combined experience, the company operates and manages a network of nursing homes and rehabilitation facilities. They deliver comprehensive solutions encompassing clinical, financial, operational, and environmental management to ensure high-quality patient care.
Sources
- Victim siteevacare.com
Source
Indexed 16 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

