Skip to main content

Ransomware victim disclosure

All victims

ARS Renacer, S.A.

listed as arsrenacer.com · Claimed by Dragonforce · listed 4 hours ago

Today
Age
since listed · data leaked

Status timeline

  1. ListedSep 20, 2026
  2. Data leakeddate unknown

At a glance

Status
Data leaked
Country
Argentina
Listed on leak site
Sep 20, 2026

About the victim

AI dossier — public-source company profile

ARS Renacer, S.A. is a private Health Risk Administrator (ARS) licensed by SISALRIL in the Dominican Republic under Law 87-01. It serves hundreds of thousands of affiliates through 24 regional offices and is a member of ADIMARS (the Dominican association of health insurers).

Industry
Health Insurance & Risk Administration

Attack summary

Severity: critical — Confirmed exfiltration of large-scale regulated healthcare data (PHI under Dominican Law 42-01 and Law 172-13) affecting hundreds of thousands of patients and affiliates, combined with financial records, IT credentials, and personal identification documents. Violation of mandatory SISALRIL protections. Multiple paths for harm: patient blackmail, identity theft, unauthorized medical transfers, and financial fraud.

DragonForce claims to have exfiltrated 274,404 files (158,693 classified as critical/high-risk) from ARS Renacer's systems. The dump includes medical records (diagnoses, procedures, pre-certifications, prescriptions), personally identifiable information (national ID numbers, names, addresses, phone numbers), employee credentials and SSH keys, payroll data, financial transaction details, and bank account information for hundreds of thousands of affiliates and patients.

critical

Data the group says was taken

AI dossier — extracted from the leak post
  • Medical service authorization records with diagnoses and procedures
  • Pre-certification and treatment authorization files
  • Medical records (expediente clínico)
  • Prescription files linked to diagnoses
  • Claims files containing PHI
  • National ID numbers (cédulas) and personal identification
  • Affiliate names, addresses, phone numbers
  • Financial transaction records and bank details
  • Employee payroll data
  • IT personnel SSH keys and command history
  • System access credentials and authentication tokens
  • Financial system passwords and tokens
  • Database backups
  • Board of Directors contact and identity data

What the group claims

ARS RENACER, S.A. DUMP: ANALYSIS OF A HEALTH INSURANCE COMPANY LEAK ═══════════════════════════════════════════════════ ARS Renacer, S.A. (Dominican Republic) is a private Health Risk Administrator (ARS), licensed by SISALRIL (Law 87-01). Member of ADIMARS. It serves hundreds of thousands of affiliates through 24 regional offices. **DUMP VOLUME:** 274,404 files / 158,693 critical and high-risk files ▸ 50,894 files in the "Usuarios" (Users) folder — user accounts for all systems ▸ .ssh/ + .bash_history + .gitconfig — access keys and command history of IT personnel ▸ 4,501 files — direct affiliate databases (names, cédulas [national IDs], phone numbers, addresses) ▸ 3,000 backup files — potentially complete database dumps ▸ 679 files — employee payroll data ▸ 500 files — passwords and access tokens to financial systems **MEDICAL DATA (PHI):** ▸ 19,443 medical service authorization files — diagnoses, procedures, patient names ▸ 13,928 pre-certification files ▸ 810 pre-certification files (treatment details) ▸ 199 medical record files (expediente clínico) ▸ 1,569 prescription files linked to diagnoses ▸ 252 claims files containing PHI **FINANCIAL DATA:** ▸ 4,863 financial transaction files — payments, refunds, bank details ▸ 3,676 account files with affiliates' financial data ▸ 3,467 financial documents (reports, balance sheets, budgets) ▸ 1,293 files containing financial system secrets and tokens **REGULATORY RISKS:** ▸ Law 172-13 (Personal Data Protection) — Article 13 directly violated; penalties: 6 months to 2 years in prison + fines up to 150 minimum wages per incident ▸ Law 42-01, Article 28 (Confidentiality of clinical records) ▸ Law 53-07 (Cybercrime) — mandatory DICAT investigation ▸ Circular SSRL-INT-2025-000827 SISALRIL — direct requirement to protect PHI ▸ Precedent: SISALRIL fine of 2.3 million DOP for 5 incidents (2021); the current leak is orders of magnitude larger **OTHER RISKS:** ▸ Exploitation of the Traspaso Digital system (SISALRIL, 2025) for massive illegal transfers of affiliates using leaked credentials ▸ Blackmailing patients with the threat of disclosing diagnoses ▸ BEC (Business Email Compromise) attacks on management (Board of Directors' data is in the dump) ▸ Synthetic identity theft and fabrication of fake cédulas ▸ Mass Habeas Data lawsuits — will paralyze the legal department The dump contains a complete cross-section of the medical insurance company: from server SSH keys to the diagnoses of hundreds of thousands of patients and affiliates' bank details. The data cannot be invalidated — a cédula and medical history are immutable.

Sources

Source

Indexed 4 hours ago

This page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.

Is this your supplier? Your competitor? You?

Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

Disclosure context

About Dragonforce

Dragonforce is a relatively new ransomware group that emerged in December 2023, operating with apparent financial motivations based on their targeting patterns and victim selection. The group's origin and potential affiliations remain unclear due to limited public documentation from established threat intelligence sources, though their rapid accumulation of 439 documented victims suggests either sophisticated capabilities or possible connections to existing ransomware infrastructure. Based on their targeting patterns across diverse sectors including manufacturing, business services, technology, and construction, Dragonforce appears to employ opportunistic attack methodologies, though specific initial access vectors, encryption methods, and extortion tactics have not been publicly detailed by major security firms or law enforcement agencies. The group has demonstrated a preference for targeting organizations primarily in English-speaking countries and Western Europe, with the United States, United Kingdom, Germany, Australia, and Italy representing their most frequent victim locations, suggesting possible language capabilities or geographic operational preferences. As of current reporting, Dragonforce appears to remain active given their recent emergence and ongoing victim acquisition, though the lack of detailed public analysis from major threat intelligence organizations indicates either operational security measures that have limited researcher visibility or that the group has not yet conducted sufficiently high-profile attacks to warrant extensive public documentation by CISA, FBI, or established security research firms. The group has been linked to 670 public disclosures across our corpus. First observed on a leak site on December 13, 2023; most recent post September 20, 2026. The operation is currently active.

Also tracked as: DRAGON FORCE.

Timeline of this disclosure

  • September 20, 2026arsrenacer.com listed by Dragonforce on the group's public leak site

Sector and geography

Geographically, arsrenacer.com is reported in Argentina, a country with 32 ransomware disclosures in our corpus.

If your organisation is affected

A listing by Dragonforce means arsrenacer.com appeared on a ransomware extortion site and data attributed to it has been published. If this is your organisation, or a supplier you depend on, the priority is to confirm the intrusion and contain it before the window to act closes.

  • Engage your incident-response team and preserve forensic evidence before remediating — do not wipe affected systems first.
  • Force a password reset and revoke active sessions for exposed accounts; rotate any credentials, API keys or certificates that may have been in the stolen data.
  • Assess regulatory notification duties (GDPR, NIS2, sector regulators) — many carry a 72-hour reporting clock from awareness.
  • Monitor for the data appearing on Dragonforce's leak site and across paste and breach channels, and brief downstream partners who may be exposed through you.

How we know this. Darkfield monitors public ransomware leak sites continuously, archiving every new disclosure and the data later released against the victim. Each entry on this page is sourced from the operator's own publication and cross-checked against complementary OSINT feeds (RansomLook, ransomware.live, RansomWatch). We do not collect or host stolen data — only the metadata, timestamps and screenshots needed to make the public disclosure searchable and accountable. Records here are corrected when the original post is edited, retracted, or merged with another disclosure.