Ransomware victim disclosure
← All victimsElmwood Healthcare
listed as elmwoodhomecare.com · Claimed by Lockbit5 · listed 3 months ago
Status timeline
- ListedMar 30, 2026
- Data leakeddate unknown
At a glance
- Group
- Lockbit5
- Status
- Data leaked
- Country
- United Kingdom
- Sector
- Healthcare
- Listed on leak site
- Mar 30, 2026
About the victim
AI dossier — public-source company profileElmwood Healthcare is a Medicare-certified, nationally accredited home-based care organisation operating in the United Kingdom. The company provides in-home care services to patients, operating under accreditation standards consistent with a regulated healthcare provider. Its web presence is maintained at elmwoodhomecare.com.
- Industry
- Home-Based Healthcare Services
Attack summary
Severity: critical — The victim is a Medicare-certified home healthcare provider handling regulated medical and personal health information (PHI/PII). Data has been published, confirming exfiltration of likely sensitive patient and healthcare data subject to HIPAA-equivalent regulations, representing a critical-severity breach.LockBit 5 claims to have exfiltrated data from Elmwood Healthcare, with the disclosure status recorded as data_published, indicating stolen data has been released or made available. The specific data types and volume have not been quantified in the available post excerpt.
Data the group says was taken
AI dossier — extracted from the leak post- Patient records
- Medicare/insurance data
- Employee personal information
- Healthcare operational data
What the group claims
Elmwood Healthcare is a Medicare certified, nationally accredited home-based care organization opera...
Sources
Source
Indexed 3 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

