Critical Unverified

AmorSaúde Ransomware Claim by LockBit5 (Sep 2026)

By Yazoul AI · automated

Unverified dark web claim. This report is based on a post observed on a dark web forum. Yazoul Security has not independently verified the authenticity of this claim.

Leak Site Screenshot

Leak site post claiming amorsaude.com.br data breach

Screenshot captured at time of discovery. Image blurred to protect victim PII.

Leak site post claiming amorsaude.com.br data breach - full size

Claim Summary

On September 9, 2026, the ransomware group tracked as “lockbit5” allegedly listed AmorSaúde (amorsaude.com.br), a Brazilian healthcare provider network, on its dark web leak site. According to the threat actor’s post, the victim is described as a rapidly growing network of popular clinics in Brazil offering medical, dental, and related services. The group claims to have exfiltrated data, though no data volume was disclosed in the listing.

This claim has NOT been independently verified by Yazoul Security or any third party. It remains a single-source assertion published by the threat actor itself. No sample files, proof packs, or download links are referenced in this report, and none should be sought.

Threat Actor Profile

The claim is attributed to lockbit5, a moniker that appears to reference the broader LockBit ransomware lineage. It is important to note that the original LockBit operation was heavily disrupted by international law enforcement action in 2024, and numerous copycat or successor personas have since adopted variations of the name. Whether “lockbit5” represents a genuine continuation, a rebrand, or an unrelated actor trading on brand recognition is currently unclear.

Public research on this specific persona is essentially absent. Yazoul Security has no confirmed tooling list, no verified affiliate structure, and no established victim count for lockbit5. Historically, groups using the LockBit name have favored double extortion, initial access via exposed remote services and phishing, and the use of commodity and custom encryptors. However, those tactics should be treated as general LockBit-family patterns, not confirmed behavior for this actor.

Given the lack of track record, the group’s credibility on this specific claim is unknown. Groups with thin or unverifiable histories are more likely to exaggerate, recycle old data, or post claims they cannot substantiate.

Alleged Data Exposure

The leak site entry claims data was taken from AmorSaúde, but provides no volume figure, no file listing, and no proof of exfiltration beyond the assertion itself. The description text appears to be drawn from public marketing language about the organization rather than from internal documents, which is a common pattern in low-confidence claims.

No categories of data - such as patient records, employee information, or financial documents - have been specified by the actor. For a healthcare provider, any genuine breach would carry sensitive-data implications, but at this stage there is no evidence to confirm what, if anything, was actually accessed.

Potential Impact

If the claim were substantiated, a healthcare network in Brazil could face regulatory scrutiny under the LGPD (Lei Geral de Proteção de Dados), operational disruption to clinic services, and reputational harm. Patient trust is particularly fragile in the healthcare sector.

However, ransomware groups routinely exaggerate or fabricate claims to pressure victims into paying. An unverified listing with no disclosed data volume and no proof pack should be treated with significant skepticism until corroborated.

What to Watch For

  • Whether the group publishes a proof pack or sample files, which would raise confidence.
  • Any official statement from AmorSaúde or Brazilian data protection authorities (ANPD).
  • Whether the listing is removed, updated, or left to expire, which can indicate negotiation or a bluff.
  • Reuse of the “lockbit5” name across other victims, which may clarify whether it is an active operation or a short-lived persona.

Organizations in the healthcare sector should review remote access exposure, enforce multi-factor authentication, and monitor for credential-stuffing activity regardless of this specific claim.

Disclaimer

This report is based solely on an unverified claim published by a threat actor on a dark web leak site. Yazoul Security has NOT independently confirmed the attack, the exfiltration of data, or the involvement of the named group. All statements should be read as allegations. Ransomware operators frequently misrepresent victims, inflate data volumes, and recycle prior breaches. No personal data, credentials, samples, or access instructions are included here by design. Readers should await official confirmation before drawing conclusions.

Share:

Never miss a threat intelligence alert

Get real-time security alerts delivered to your preferred platform.

Related Claims

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.