Ransomware victim disclosure
← All victimsCasa Médica
listed as casamedica.com.gt · Claimed by benzona · listed 4 months ago
Status timeline
- Listed
Jan 30, 2026
- Data leaked
At a glance
- Group
- benzona
- Status
- Data leaked
- Country
- GT
- Sector
- Healthcare
- Listed on leak site
- Jan 30, 2026
About the victim
AI dossier — public-source company profileCasa Médica is a Guatemala-based retailer specialising in medical equipment, supplies, and healthcare products. Their catalogue spans diabetes management devices, home care equipment, orthopaedic supports, respiratory therapy devices, diagnostic equipment, and hospital furniture. They also operate a nutritional clinic and offer home-delivery services.
- Industry
- Medical Equipment & Supplies Retail
Attack summary
Severity: high — The disclosure status is data_published, indicating actual data has been released. As a healthcare-adjacent retailer handling customer medical purchases and potentially patient health-related information, the exfiltration of business and customer data carries significant sensitivity even without a confirmed volume figure.The ransomware group Benzona claims to have exfiltrated data from Casa Médica, with the disclosure status recorded as data_published, though no ransom amount or specific data volume was stated in the leak post.
Data the group says was taken
AI dossier — extracted from the leak post- Customer records
- Business/operational data
- Medical product order data
- Potentially patient or clinic data
Original description
AI-summarised, not from the leak post"Casamedica.com.gt" is a Guatemala-based company that provides a range of medical equipment and supplies. Their product range includes everything from surgical instruments to hospital furniture and diagnostic equipment. Not just limited to sales, Casamedica also provides maintenance services for the equipment. They aim to improve the healthcare sector by catering to the specific needs of professionals in the field.
Sources
- Victim sitecasamedica.com.gt
Source
Indexed 4 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
