Ransomware victim disclosure
← All victimsInstituto Ferrero de Neurología y Sueño
Claimed by Kazu · listed 16 hours ago
Status timeline
- ListedAug 23, 2026
- Data leakeddate unknown
At a glance
- Group
- Kazu
- Status
- Data leaked
- Country
- Argentina
- Sector
- Healthcare
- Listed on leak site
- Aug 23, 2026
About the victim
AI dossier — public-source company profileInstituto Ferrero de Neurología y Sueño (IFN) is a specialized medical center in Buenos Aires, Argentina, focusing on the diagnosis and treatment of neurological and sleep disorders. It offers neurology consultations, sleep studies, diagnostic testing, and personalized treatment plans, staffed by board-certified specialists using advanced medical technology.
- Industry
- Healthcare - Neurology & Sleep Medicine
- Address
- Junín 1120, Buenos Aires, Argentina
Attack summary
Severity: low — No proof files, screenshots, or specific data exfiltration confirmed in the post. The leak post is a generic announcement with no operational impact or evidence of data compromise described.The kazu group claims to have attacked IFN but the leak post contains no specific details of what data was exfiltrated, encrypted, or compromised. No data inventory or proof files are described in the available post excerpt.
Data the group says was taken
AI dossier — extracted from the leak post- Patient medical records
- Personal identifiable information
What the group claims
Instituto Ferrero de Neurología y Sueño (IFN) is a specialized medical center in Argentina that focuses on the diagnosis and treatment of neurological and sleep disorders. It provides services such as neurology consultations, sleep studies, diagnostic testing, and personalized treatment plans. Using advanced medical technology and a team of specialists, IFN helps patients receive comprehensive care for conditions affecting the brain, nervous system, and sleep health.
Sources
- Victim siteifn.com.ar
Source
Indexed 16 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

