Ransomware victim disclosure
← All victimsCS Caritas Socialis
listed as cs.at · Claimed by Lockbit5 · listed 4 months ago
Status timeline
- ListedFeb 14, 2026
- Data leakeddate unknown
At a glance
- Group
- Lockbit5
- Status
- Data leaked
- Country
- Austria
- Sector
- Technology
- Listed on leak site
- Feb 14, 2026
About the victim
AI dossier — public-source company profileCS Caritas Socialis is an Austrian Catholic charitable organisation based in Vienna that provides a comprehensive range of nursing and care services. Its offerings include home care, day centres for seniors, long-term residential care, Alzheimer and dementia specialist facilities, hospice services, multiple sclerosis care, kindergartens, and a mother-and-child shelter. It operates multiple specialist facilities across Vienna and is a significant non-profit healthcare provider in Austria.
- Industry
- Healthcare & Social Services (Nursing, Hospice & Elderly Care)
- Address
- Vienna, Austria
Attack summary
Severity: critical — CS Caritas Socialis handles highly sensitive medical, personal, and social care data for vulnerable populations including elderly, terminally ill, dementia, MS, and domestic-violence-affected individuals. Data publication by the group indicates confirmed exfiltration of what is almost certainly regulated health and personal data (PII at scale, medical records) for a healthcare/social-care provider, meeting the critical threshold.LockBit 5 claims to have attacked CS Caritas Socialis and has published data (disclosed status: data_published), suggesting exfiltration of organisational data. The specific data categories and volume have not been detailed in the available leak post excerpt.
Data the group says was taken
AI dossier — extracted from the leak post- Patient/resident care records
- Personal health information
- Employee records
- Organisational/administrative documents
- Donor and financial records
What the group claims
CS Pflege & Betreuung Die CS Caritas Socialis bietet Pflege- und Betreuungsangebote aus einer Hand:...
Sources
Source
Indexed 4 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

