Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

CERT Polska Details Coordinated Cyber Attacks on 30+ Wind and Solar Farms

February 7, 2026

Researchers Uncover Chrome Extensions Abusing Affiliate Links and Stealing ChatGPT Access

February 7, 2026

China-Linked UAT-8099 Targets IIS Servers in Asia with BadIIS SEO Malware

February 7, 2026
Facebook X (Twitter) Instagram
Sunday, February 8
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»KillSec Ransomware Hits Brazilian Healthcare IT Vendor
News

KillSec Ransomware Hits Brazilian Healthcare IT Vendor

Team-CWDBy Team-CWDSeptember 11, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


A ransomware attack claimed by the group KillSec has disrupted MedicSolution, a software provider serving Brazil’s healthcare sector.

On September 8 2025, the hackers reportedly threatened to leak stolen data unless negotiations were initiated.

According to a new advisory by Resecurity, the breach could affect a wide range of medical providers and patients, given MedicSolution’s central role in the healthcare supply chain.

Supply Chain Breach and Data Exposure

By targeting a software vendor instead of a single clinic, the attackers expanded their reach dramatically.

Resecurity stated that the group obtained more than 34 GB of data comprising 94,818 files, including:

  • Medical evaluations

  • Lab results

  • X-rays

  • Unredacted patient photos, including body images

  • Records related to minors

The stolen files appear to involve institutions such as Vita Exame, Clinica Especo Vida, Centro Diagnostico Toledo, Labclinic and Laboratório Alvaro.

Read more on healthcare data breaches: Healthcare Sector Takes 58 Days to Resolve Serious Vulnerabilities

KillSec has previously targeted Brazilian entities, leaking personal and financial data from government systems. The latest incident, however, strikes directly at healthcare operations. Stolen medical records can be used for extortion, causing harm to both providers and patients.

According to Resecurity, the data was not taken through a complex hack but was left exposed in misconfigured AWS cloud buckets.

The exposure highlights persistent gaps in incident response and monitoring across the sector.

Despite outreach from investigators, MedicSolution has not issued a public response.

Wider Campaign and Regulatory Context

The attack is part of a broader campaign in Latin America and beyond. In recent weeks, KillSec has claimed responsibility for breaches at Archer Health in the US, Suiza Lab in Peru, and Colombian providers GoTelemedicina and eMedicoERP.

One month earlier, the group leaked data from Doctocliq, a Peruvian platform serving more than 3500 doctors in 20 countries.

Healthcare organizations in Brazil are bound by the Lei Geral de Proteção de Dados (LGPD), which classifies health data as sensitive and requires strong safeguards, explicit consent and breach reporting within three business days.

The Autoridade Nacional de Proteção de Dados (ANPD) enforces compliance and has issued fines totaling over BRL 98 million ($20m USD) across all sectors since 2023, with healthcare among the hardest hit.

Resecurity warned that KillSec may still be preparing further disclosures in Brazil, underlining the sector’s ongoing vulnerability to cybercrime.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleLNER Reveals Supply Chain Attack Compromised Customer Information
Next Article Adobe Releases Patch for Critical Flaw in Commerce and Magento
Team-CWD
  • Website

Related Posts

News

CERT Polska Details Coordinated Cyber Attacks on 30+ Wind and Solar Farms

February 7, 2026
News

Researchers Uncover Chrome Extensions Abusing Affiliate Links and Stealing ChatGPT Access

February 7, 2026
News

China-Linked UAT-8099 Targets IIS Servers in Asia with BadIIS SEO Malware

February 7, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Exploit Threat Intel Platforms For Phishing

September 7, 20256 Views

U.S. Treasury Sanctions DPRK IT-Worker Scheme, Exposing $600K Crypto Transfers and $1M+ Profits

September 5, 20256 Views

Ukrainian Ransomware Fugitive Added to Europe’s Most Wanted

September 11, 20255 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Exploit Threat Intel Platforms For Phishing

September 7, 20256 Views
Our Picks

Why LinkedIn is a hunting ground for threat actors – and how to protect yourself

January 16, 2026

What are brushing scams and how do I stay safe?

December 24, 2025

What it is and how to protect yourself

January 8, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.