Ransomware victim disclosure
← All victimsmedicalnetworks CJ GmbH & Co. KG
Claimed by Dragonforce · listed 2 months ago
Status timeline
- ListedApr 17, 2026
- Data leakeddate unknown
At a glance
- Group
- Dragonforce
- Status
- Data leaked
- Country
- Germany
- Sector
- Healthcare
- Listed on leak site
- Apr 17, 2026
About the victim
AI dossier — public-source company profilemedicalnetworks CJ GmbH & Co. KG is a German healthcare IT company operating the platform medicalnetworks.de. The company provides integrated care solutions, including its 'ascleon® care' product, Hybrid-DRG billing under §115f, and services for statutory health insurers (Krankenkassen), including remote maintenance and online practice management tools. It operates in the German healthcare sector, facilitating digital coordination between insurers, clinicians, and care networks.
- Industry
- Healthcare IT & Integrated Care Management
Attack summary
Severity: critical — The victim operates in German regulated healthcare IT, handling data for statutory health insurers and integrated care networks. Exfiltration of such data almost certainly involves regulated patient and health-insurer PII at scale, triggering GDPR and German healthcare data-protection obligations.DragonForce claims to have exfiltrated data from medicalnetworks CJ GmbH & Co. KG and has published the data; no ransom amount was stated and no specific data volume was disclosed in the post.
Data the group says was taken
AI dossier — extracted from the leak post- Health insurer (Krankenkassen) data
- Integrated care management records
- Patient or practice management data
- Corporate documents
- Login/access credentials (remote maintenance system)
What the group claims
Medicalnetworks specializes in integrated healthcare solutions, offering services such as ascleoncare and Hybrid-DRG billing. Their products are designed to streamline processes for health insurance providers and medical practices. The company aims to enhance the efficiency of healthcare delivery through innovative technology. Their intended clients include healthcare providers and insurance companies seeking to improve their operational workflows
The leak post
captured from the group's site```
{"data":{"count":483,"publications":[{"uuid":"b008b8b7-0e47-416f-adcd-2313d8136de4","created_at":"2026-05-08T20:56:13.122134Z","name":"CF Evans Construction","website":"www.cfevans.com","address":"125 Regional Pkwy Ste 200, Orangeburg, South Carolina, 29118, United States","description":"A recognized leader in the multi-family housing construction industry, CF Evans Construction provides a product for developers. The company has thrived amid six decades.\nThe data of this company includes:\n Corporate correspondence of senior executives\n Financial documents\n HR documents\n Accounting documents\n Certificates, contracts, passwords, databases, and much more.","weight":4775795351552,"is_timer_publication_stopped":false,"timer_publication":"2026-05-22T07:48:00Z","try_again":false,"tags":[],"logo_uuid":"f4e582dd-6562-4590-bac8-2b9e5c564853","is_transfering":false},{"uuid":"3827192f-9bb3-490c-9c1c-d28b382510cd","created_at":"2026-05-08T17:53:24.736605Z","name":"CMC Expertise Comptable","website":"cmcexpertise.fr","address":"32 Rue De La Clairière, Fort-de-France,","description":"CMC Expertise Comptable is a certified accounting firm located in Martinique, dedicated t…Sources
Source
Indexed 2 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

