Ransomware victim disclosure
← All victimsSecretaria de Estado de Saúde de Mato Grosso (SES-MT)
listed as saude.mt.gov.br · Claimed by Lockbit5 · listed 5 hours ago
Status timeline
- ListedJun 20, 2026
- Data leakeddate unknown
At a glance
- Group
- Lockbit5
- Status
- Data leaked
- Country
- Brazil
- Sector
- Public Sector
- Listed on leak site
- Jun 20, 2026
About the victim
AI dossier — public-source company profileThe State Secretariat of Health of Mato Grosso (SES-MT) is the primary executive body responsible for public health administration in the state of Mato Grosso, Brazil. It manages the state's health system including hospitals, health surveillance, pharmaceutical assistance, and oversight of the Unified Health System (SUS) operations across the state.
- Industry
- Public Health Administration
- Address
- Palácio Paiaguás, Rua D, S/N, Bloco 5 - Centro Político Administrativo, Cuiabá - MT - 78049-902, Brazil
Attack summary
Severity: critical — State health authority compromised with confirmed data publication; likely exposure of healthcare PII at scale, patient medical records, and operational health system data. Healthcare sector is regulated/sensitive infrastructure at state level.LockBit5 claims to have accessed the SES-MT systems. The leak post indicates data has been published, though specific details on the scope of exfiltration versus encryption are not fully detailed in the truncated post excerpt provided.
Data the group says was taken
AI dossier — extracted from the leak post- health administrative records
- patient data
- pharmaceutical records
- hospital management systems
- personnel records
- financial/procurement data
What the group claims
The State Secretariat of Health of Mato Grosso (SES-MT) serves as the primary executive body of the...
Sources
Source
Indexed 5 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

