Ransomware victim disclosure
← All victimsNúcleo de Diagnóstico
listed as nucleodediagnostico.mx · Claimed by Lockbit5 · listed 2 months ago
Status timeline
- ListedApr 14, 2026
- Data leakeddate unknown
At a glance
- Group
- Lockbit5
- Status
- Data leaked
- Country
- Mexico
- Sector
- Healthcare
- Listed on leak site
- Apr 14, 2026
About the victim
AI dossier — public-source company profileNúcleo de Diagnóstico is a clinical analysis laboratory (laboratorio de análisis clínicos) located in Guadalajara, Mexico. The company provides diagnostic testing services to patients and is currently undergoing a service redesign, as indicated by a countdown page on its public website. The scale of operations is not publicly specified.
- Industry
- Clinical Laboratory & Diagnostic Services
- Address
- Guadalajara, Mexico
Attack summary
Severity: critical — The victim is a clinical diagnostic laboratory in the healthcare sector handling regulated medical and patient PII data. The data has been published by the ransomware group, confirming exfiltration of likely sensitive health/medical records, which meets the critical threshold.The LockBit 5 group claims to have attacked Núcleo de Diagnóstico and has published data (disclosed status: data_published), indicating exfiltration of data from this clinical laboratory. The specific data categories and volume have not been detailed in the available post excerpt.
Data the group says was taken
AI dossier — extracted from the leak post- Patient clinical records
- Diagnostic test results
- Personal health information
What the group claims
Núcleo de Diagnóstico Núcleo de Diagnóstico es un laboratorio de análisis clínicos ubicado en Guada...
Sources
Source
Indexed 2 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

