Ransomware victim disclosure
← All victimsSabin Medicina Diagnóstica
listed as Sabin · Claimed by Nokoyawa · listed 3 years ago
Status timeline
- Listed
May 23, 2023
- Data leaked
At a glance
- Group
- Nokoyawa
- Status
- Data leaked
- Country
- Brazil
- Sector
- Healthcare
- Listed on leak site
- May 23, 2023
About the victim
AI dossier — public-source company profileSabin Medicina Diagnóstica is one of Brazil's leading medical diagnostics companies, offering a wide range of high-precision laboratory tests and diagnostic services. The company is headquartered in Brasília, Brazil, and operates an extensive network of collection units across multiple Brazilian states. Sabin is widely recognized for its organizational culture and quality of customer service in the healthcare sector.
- Industry
- Medical Diagnostics & Laboratory Services
- Employees
- 1001-5000
- Founded
- 1999
Attack summary
Severity: critical — Sabin is a large-scale medical diagnostics provider; a data_published status strongly implies confirmed exfiltration of regulated health and PII data at scale, including patient medical records and diagnostic results, which constitutes sensitive regulated data under Brazilian LGPD and healthcare privacy standards.Nokoyawa claims to have compromised Sabin Laboratory and has reached the data_published stage, indicating exfiltration and publication of stolen data. The specific data categories and volume have not been explicitly quantified in the post.
Data the group says was taken
AI dossier — extracted from the leak post- Patient records
- Laboratory test results
- Personal identification information
- Employee data
- Business/organizational documents
What the group claims
Sabin Laboratory is one of the leading medical diagnostics companies in Brazil. The company is well-known for its premium customer relationship and high-precision and wide-range lab tests. Sabin's robust and healthy organizational culture has been vastly awarded in Brazil and across...
Sources
Source
Indexed 3 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
