Ransomware victim disclosure
← All victimsSanoviv Medical Institute
Claimed by Worldleaks · listed 4 months ago
Status timeline
- ListedFeb 10, 2026
- Data leakeddate unknown
At a glance
- Group
- Worldleaks
- Status
- Data leaked
- Country
- Mexico
- Sector
- Healthcare
- Listed on leak site
- Feb 10, 2026
About the victim
AI dossier — public-source company profileSanoviv Medical Institute is a holistic hospital and health-wellness facility located in Rosarito Beach, Baja California, Mexico. It specializes in integrative medicine, nutritional therapies, detoxification, functional medicine, and mind-body healing. The institute offers inpatient programs addressing chronic degenerative illnesses and preventative healthcare.
- Industry
- Integrative & Holistic Medicine
- Address
- Rosarito Beach, Baja California, Mexico
Attack summary
Severity: high — The victim is a healthcare facility handling sensitive patient medical records and personal health information; the status is 'data_published', indicating actual data was released. Medical data from inpatient programs constitutes regulated, sensitive PII and health information, warranting at minimum a high severity rating. Insufficient detail to confirm scale required for critical.The worldleaks group claims to have compromised Sanoviv Medical Institute and has published data associated with the attack. The specific nature of data exfiltrated or encryption activity is not detailed in the post, but the disclosure status is marked as data_published.
Original description
AI-summarised, not from the leak postSanoviv Medical Institute is a health and wellness facility located in Rosarito Beach, Mexico. This holistic hospital specializes in integrative medicine, nutritional therapies, detoxification, functional medicine, and mind-body healing therapies. Offering inpatient programs, the facility focuses on treating a variety of health issues, including chronic degenerative illnesses and preventative health care.
Sources
Source
Indexed 4 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

