Ransomware victim disclosure
← All victimsVigilia
Claimed by Global · listed 3 days ago
Status timeline
- ListedAug 28, 2026
- Data leakeddate unknown
At a glance
- Group
- Global
- Status
- Data leaked
- Country
- Uruguay
- Sector
- Technology
- Listed on leak site
- Aug 28, 2026
About the victim
AI dossier — public-source company profileVigilia is a Uruguayan healthcare services and insurance company offering home care, ambulance transportation, medical consultation coordination, and companion assistance services. Operating from Montevideo with multiple branch locations, it provides insurance policies covering surgical procedures, accidents, and in-home nursing care.
- Industry
- Healthcare & Insurance Services
- Address
- Montevideo, Uruguay (multiple branches: Maldonado, Las Piedras, San Carlos)
Attack summary
Severity: high — Confirmed data exfiltration from a healthcare and insurance services company handling sensitive personal health information, customer records, and insurance policy data at scale. Healthcare data is regulated and inherently sensitive.The ransomware group claims to have targeted Vigilia and published exfiltrated data. The leak post does not specify the nature of the data compromised or the operational impact (encryption, exfiltration, or both).
Data the group says was taken
AI dossier — extracted from the leak post- customer personal information
- insurance policy records
- medical consultation records
- administrative data
What the group claims
VIGILIA is a company that provides support and care services for people. It offers assistance in medical facilities, home care, ambulance transportation, and related administrative support. The company also provides insurance policies and helps coordinate medical consultations and tests.
Sources
- Victim sitevigilia.com.uy
Source
Indexed 3 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

