Ransomware victim disclosure
← All victimsBEHCA
Claimed by Kill Security 3.0 · listed 4 hours ago
Status timeline
- Listed
Jun 4, 2026
- Data leaked
At a glance
- Group
- Kill Security 3.0
- Status
- Data leaked
- Country
- United States
- Listed on leak site
- Jun 4, 2026
- Data size
- 600 GB
About the victim
AI dossier — public-source company profileBEHCA is a United States-based company operating in the healthcare technology and behavior tracking sector. Limited public information is available.
Attack summary
Severity: high — 600 GB of confirmed data exfiltration from a healthcare technology company indicates significant scale and sensitivity; healthcare sector data is regulated and sensitive by nature.Kill Security 3.0 claims to have exfiltrated approximately 600 GB of data from BEHCA. The group has published the data and provided no ransom demand.
Data the group says was taken
AI dossier — extracted from the leak post- proprietary healthcare/behavior tracking data
- customer/client records
- operational systems data
What the group claims
BEHCA delivers innovative behavior tracking and data analysis solutions for care providers, families, and support staff in foster care, group homes, and residential settings.
The leak post
captured from the group's siteFounded in 1997, iCare Software, based in the United States, delivers innovative management solutions for childcare and afterschool programs. Serving childcare centers, preschools, afterschool programs, and multi-site operations, iCare automates critical tasks like attendance tracking, staff scheduling, tuition collection, and compliance reporting. Its unique offerings include AI-driven analytics, business intelligence dashboards, and CRM tools to boost enrollment and staff retention. With seamless data migration and robust back-end technology, iCare empowers providers to focus on quality care while streamlining operations and driving growth. Cadorim simplifies money transfers to Mauritania, offering a secure, user-friendly platform for individuals and businesses. With a focus on speed, affordability, and accessibility, Cadorim enables seamless transactions in just three clicks, available around the clock. The company ensures maximum security for every transfer, provides competitive exchange rates with no fees, and processes transactions instantly. Headquartered in Brussels, Belgium, with operations in Nouakchott, Mauritania, Cadorim serves customers seeking reliable, cost-effectiv…
Screenshot of the leak post

Sources
Source
Indexed 4 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.
