Instituto de Cancerología y Hospital Dr. Bernardo del Valle S. Data Breach

Alleged

Ransomware claim involving Instituto de Cancerología y Hospital Dr. Bernardo del Valle S.

Published: Sep 3, 2026 Krybit
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Instituto de Cancerología y Hospital Dr. Bernardo del Valle S.
Industry
Healthcare
Threat Actor
Krybit
Date of Incident
Sep 3, 2026

Executive Summary

The ransomware group krybit listed Instituto de Cancerología y Hospital Dr. Bernardo del Valle S. on its dark web portal on September 3, 2026. The organization, identified by the domain ligacancerguate[.]org, is Guatemala’s leading institution for cancer treatment and research. This listing was detected by SOCRadar Dark Web Monitoring. The Instituto de Cancerología y Hospital Dr. Bernardo del Valle S. has not yet confirmed the claim. Given the nature of a cancer hospital, the potential impact of a data breach is exceptionally severe, involving sensitive oncology records, patient diagnoses, and donor information, placing it at the extreme end of data sensitivity for healthcare organizations. In the 60 days preceding this listing, krybit claimed 58 victims. The group’s activity during this period shows a distribution of victims by country as India (leading), Thailand, and Brazil, and by sector as professional services, general, and healthcare. The inclusion of Instituto de Cancerología y Hospital Dr. Bernardo del Valle S. marks krybit’s first claimed Guatemalan victim within this timeframe. Notable healthcare comparables in the 60-day period include Seashell Hospital (India), Jindal Life Science Private Limited (India), and Vedantaa Institute of Medical Sciences (India). Additionally, the listing of The Union for International Cancer Control (Switzerland), which operates in professional services, suggests a thematic overlap as krybit has demonstrated a pattern of targeting organizations related to cancer research and treatment more than once.

Technical Analysis

krybit’s documented access methodology aligns with common practices in the broader ransomware ecosystem. This typically involves the acquisition of infostealer-sourced credentials from underground markets. These credentials are then validated and used to gain access to systems through platforms such as Microsoft 365, VPNs, or other web-facing portals, preceding the deployment of ransomware. Healthcare institutions in Latin America are particularly susceptible to such attacks due to often operating with legacy infrastructure that may have limited security tooling, thereby increasing their exposure to these threats. Stealer-log telemetry queries for ligacancerguate[.]org returned no records within the observed dataset. However, it is important to note that this coverage is paginated, and the absence of records does not rule out exposure via sub-domains or personal email aliases. Therefore, this null result constrains the picture but does not definitively confirm that the organization is unaffected. The listing of a cancer hospital under extortion poses significant public health and patient safety risks. If sensitive data is released or critical systems remain encrypted, the implications for patient care and organizational operations are severe. Consequently, any response prioritization should reflect this heightened risk, considering continuous dark web monitoring, proactive credential hygiene checks, password rotation, and multi-factor authentication review.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.