Ransomware victim disclosure
← All victims****cr*nem*ds.c*m
Claimed by devman · listed 4 months ago
Status timeline
- Listed
Jan 24, 2026
- Data leaked
At a glance
About the victim
AI dossier — public-source company profileBased on the partially redacted domain pattern '****cr*nem*ds.c*m' and the leaked post content referencing patient data and clinic records, this appears to be a medical or dental clinic operating an online presence. The country code 'SJ' corresponds to Svalbard and Jan Mayen (Norway-administered territory). No further verifiable details are available from the public site.
- Industry
- Healthcare / Medical Clinic
Attack summary
Severity: critical — The post explicitly states exfiltration and publication of patient medical records and personal health information, which constitutes regulated sensitive data (PHI/PII) and meets the threshold for critical severity regardless of scale.The group 'devman' claims to have exfiltrated patient data, medical cards, and clinic records from this medical entity, with the disclosure status marked as data_published, indicating the stolen data has been released.
Data the group says was taken
AI dossier — extracted from the leak post- Patient data
- Medical cards
- Clinic records
What the group claims
Patient data, medical cards clinic records
Sources
Source
Indexed 4 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
