Ransomware victim disclosure
← All victimsCooperativa de Hospitales de Antioquia - COHAN
Claimed by Qilin · listed 4 days ago
Status timeline
- Listed
May 17, 2026
Current state: Listed for ransom
At a glance
- Group
- Qilin
- Status
- Listed for ransom
- Country
- Colombia
- Sector
- Healthcare
- Listed on leak site
- May 17, 2026
About the victim
AI dossier — public-source company profileCooperativa de Hospitales de Antioquia - COHAN is a healthcare cooperative based in Antioquia, Colombia, that groups and supports a network of hospitals and healthcare institutions in the region. The organization provides shared services, supply chain, and administrative support to its member hospitals. As a cooperative structure, it serves multiple healthcare facilities across the Antioquia department.
- Industry
- Healthcare Cooperative / Hospital Network
Attack summary
Severity: medium — The victim operates in the healthcare sector, which handles regulated and sensitive patient and administrative data. However, the post is a bare listing with no proof files, no confirmed exfiltration, and no data size disclosed, preventing a higher severity rating despite the sensitive sector.The Qilin ransomware group has listed Cooperativa de Hospitales de Antioquia - COHAN as a victim on their leak site. The post represents an initial listing with no explicit detail on data exfiltrated, ransom demanded, or encryption confirmed.
The leak post
captured from the group's site[Australian College of Business Intelligence](http://ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion/site/blog?uuid=5ecb65aa-3960-4b61-ab37-802b4eb3d3d5) [Cooperativa de Hospitales de Antioquia - COHAN](http://ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion/site/blog?uuid=bd0eebf4-e436-4f46-b7d8-0c21f8fff528) [John G Yphantides A Professional Law](http://ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion/site/blog?uuid=1e464ce5-6e74-4e62-be0b-eac503e43af8) Law Firms & Legal Services Law Firms & Legal Services
Sources
Source
Indexed 4 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
