Ransomware victim disclosure
← All victimsDYSA Healthcare S.A.
listed as DYSA · Claimed by Thegentlemen · listed 2 months ago
Status timeline
- ListedApr 8, 2026
- Data leakeddate unknown
At a glance
- Group
- Thegentlemen
- Status
- Data leaked
- Country
- Mexico
- Listed on leak site
- Apr 8, 2026
About the victim
AI dossier — public-source company profileDYSA Healthcare S.A. is a family-founded Paraguayan company co-founded by Ricardo Hellmers Fonseca and Florencia Llano de Hellmers. The company is dedicated to supplying healthcare technologies and services to hospitals and medical professionals throughout Paraguay.
- Industry
- Healthcare Technology & Medical Equipment Supply
- Address
- Paraguay
Attack summary
Severity: high — The disclosure status is 'data_published', indicating confirmed data exfiltration and release. The victim operates in the healthcare sector, which typically involves regulated and sensitive data (patient records, medical professional information, hospital contracts), elevating severity to high; insufficient detail exists to confirm PII at scale that would warrant critical.The group 'thegentlemen' claims to have attacked DYSA Healthcare S.A. and has published data (disclosed status: data_published), though the leak post does not specify whether encryption, exfiltration, or both occurred, nor does it detail the volume of data involved.
What the group claims
dysa.com.py DYSA Healthcare S.A. is a family-founded Paraguayan company co-founded by Ricardo Hellmers Fonseca and Florencia Llano de Hellmers, dedicated to supplying healthcare technologies and services to hospitals and medical professionals in Paraguay
Sources
- Victim sitedysa.com.py
Source
Indexed 2 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

