Hospital Santa Creu i Sant Pau Data Breach

Alleged

Ransomware claim involving Hospital Santa Creu i Sant Pau

Published: Oct 3, 2026 The Gentlemen
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Hospital Santa Creu i Sant Pau
Industry
Healthcare
Threat Actor
The Gentlemen
Date of Incident
Oct 3, 2026

Executive Summary

Hospital Santa Creu i Sant Pau, a prominent tertiary care center in Barcelona, Spain, and a UNESCO World Heritage Site, was listed by the ransomware group The Gentlemen on October 3, 2026. The group claims to have breached hospital systems and exfiltrated sensitive data. A ransomware attack on an institution of this magnitude carries significant implications for patient safety, impacting clinical, diagnostic, and administrative systems concurrently. The Gentlemen ransomware group has demonstrated a pattern of targeting healthcare institutions, with multiple claims in the past 60 days. Their operational methodology involves utilizing credentials obtained from infostealer malware for initial access, followed by extensive reconnaissance to maximize data exfiltration and encryption coverage before issuing ransom demands. The selection of a high-profile institution like Hospital Santa Creu i Sant Pau likely stems from the group’s assessment that the operational criticality and reputational sensitivity of such an organization increase leverage for a successful ransom payment.

Technical Analysis

SOCRadar’s stealer-log intelligence detected significant pre-attack credential exposure between September 14 and October 2, 2026, just one day prior to The Gentlemen’s listing of Hospital Santa Creu i Sant Pau. This exposure encompassed four key authentication surfaces: the hospital’s Microsoft identity platform (IdP), its Exchange OWA portal (correuhsp[.]santpau[.]cat), the hospital intranet, and the central authentication portal (login[.]santpau[.]cat). The most recent records, dated October 2, suggest that compromised credentials may have been fed directly into the intrusion pipeline within the final 24 hours before the public announcement of the alleged breach. The breadth of credential exposure across the hospital’s identity provider, email system, intranet, and central authentication portal indicates a high likelihood of supporting comprehensive lateral movement within the enterprise network. The proximity of the most recent credential data (October 2) to the public listing date significantly narrows the potential window for initial access acquisition to within a single day of the announcement, underscoring the immediacy of the threat. The identified credential exposure across multiple authentication systems necessitates immediate and thorough security actions. This includes the urgent force-rotation of all Microsoft IdP credentials, a detailed audit of Exchange OWA access logs for the September-October period, and a comprehensive assessment of intranet activity linked to compromised accounts. It is also crucial to activate incident response protocols in coordination with relevant national and regional authorities, such as INCIBE and Catalan health bodies. Furthermore, the hospital must evaluate potential patient data exposure in accordance with Spain’s LOPDGDD and EU GDPR breach notification regulations. During the restoration of system integrity, critical care operations should be maintained through manual backup procedures.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.