Quick Summary
AllegedExecutive Summary
Hospital Santa Creu i Sant Pau, a prominent tertiary care center in Barcelona, Spain, and a UNESCO World Heritage Site, was listed by the ransomware group The Gentlemen on October 3, 2026. The group claims to have breached hospital systems and exfiltrated sensitive data. A ransomware attack on an institution of this magnitude carries significant implications for patient safety, impacting clinical, diagnostic, and administrative systems concurrently. The Gentlemen ransomware group has demonstrated a pattern of targeting healthcare institutions, with multiple claims in the past 60 days. Their operational methodology involves utilizing credentials obtained from infostealer malware for initial access, followed by extensive reconnaissance to maximize data exfiltration and encryption coverage before issuing ransom demands. The selection of a high-profile institution like Hospital Santa Creu i Sant Pau likely stems from the group’s assessment that the operational criticality and reputational sensitivity of such an organization increase leverage for a successful ransom payment.
Technical Analysis
SOCRadar’s stealer-log intelligence detected significant pre-attack credential exposure between September 14 and October 2, 2026, just one day prior to The Gentlemen’s listing of Hospital Santa Creu i Sant Pau. This exposure encompassed four key authentication surfaces: the hospital’s Microsoft identity platform (IdP), its Exchange OWA portal (correuhsp[.]santpau[.]cat), the hospital intranet, and the central authentication portal (login[.]santpau[.]cat). The most recent records, dated October 2, suggest that compromised credentials may have been fed directly into the intrusion pipeline within the final 24 hours before the public announcement of the alleged breach. The breadth of credential exposure across the hospital’s identity provider, email system, intranet, and central authentication portal indicates a high likelihood of supporting comprehensive lateral movement within the enterprise network. The proximity of the most recent credential data (October 2) to the public listing date significantly narrows the potential window for initial access acquisition to within a single day of the announcement, underscoring the immediacy of the threat. The identified credential exposure across multiple authentication systems necessitates immediate and thorough security actions. This includes the urgent force-rotation of all Microsoft IdP credentials, a detailed audit of Exchange OWA access logs for the September-October period, and a comprehensive assessment of intranet activity linked to compromised accounts. It is also crucial to activate incident response protocols in coordination with relevant national and regional authorities, such as INCIBE and Catalan health bodies. Furthermore, the hospital must evaluate potential patient data exposure in accordance with Spain’s LOPDGDD and EU GDPR breach notification regulations. During the restoration of system integrity, critical care operations should be maintained through manual backup procedures.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.