Ransomware victim disclosure
← All victimsMUPRAS (Mutuelle de Prévoyance et d'Actions Sociales de Royal Air Maroc)
listed as www.mupras.com · Claimed by Krybit · listed 4 hours ago
Status timeline
- ListedJun 19, 2026
- Data leakeddate unknown
At a glance
- Group
- Krybit
- Status
- Data leaked
- Country
- Brazil
- Sector
- Business Services
- Listed on leak site
- Jun 19, 2026
About the victim
AI dossier — public-source company profileMUPRAS is a Moroccan mutual aid and social welfare organization affiliated with Royal Air Maroc (RAM). It provides health insurance, medical coverage, pharmaceutical benefits, and preventive services to members and their families through a network of healthcare providers including clinics, pharmacies, and specialists.
- Industry
- Health Insurance & Mutual Aid
Attack summary
Severity: high — Health insurance mutual serving Royal Air Maroc employees with confirmed data exfiltration (disclosed_status: data_published). Exposure of medical records, insurance claims, and PII at scale constitutes critical sensitive data breach.Krybit claims to have attacked MUPRAS and exfiltrated data. The group has published the disclosure but specific details of what data was taken or operational impact remain unclear from the truncated leak post.
Data the group says was taken
AI dossier — extracted from the leak post- member/subscriber records
- health insurance claim data
- medical history information
- pharmaceutical records
- personal identification data
What the group claims
MUPRAS RAM (Mutuelle de Prévoyance et d'Actions Sociales de Royal Air Maroc) is a Moroccan mutual aid and social welfar...
Sources
Source
Indexed 4 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

