Critical Unverified

Coosalud Ransomware Claim by threeam (Sep 2026)

By Yazoul AI · automated

Unverified dark web claim. This report is based on a post observed on a dark web forum. Yazoul Security has not independently verified the authenticity of this claim.

Leak Site Screenshot

Leak site post claiming coosalud.com data breach

Screenshot captured at time of discovery. Image blurred to protect victim PII.

Leak site post claiming coosalud.com data breach - full size

Claim Summary

On or around September 28, 2026, a ransomware group operating under the name “threeam” allegedly posted Coosalud (Coosalud Entidad Promotora de Salud S.A.) to its dark web leak site. According to the threat actor’s claim, the Colombian health promotion entity (EPS) was added as a victim on that date. The group has purportedly listed the organization under the healthcare sector for Colombia (CO).

Notably, the threat actor did not disclose a data volume, sample files, or a proof pack alongside the listing. This is an important detail. Ransomware operators frequently publish a victim name first and release supporting evidence later, or sometimes never at all. As of this writing, no data samples, file trees, or exfiltration proof have been observed in connection with this claim.

The claim remains entirely unverified. Coosalud has not publicly confirmed or denied the allegation at the time of writing, and no independent third party has validated the group’s assertions.

Threat Actor Profile

The group behind this claim, threeam, is a relatively low-profile ransomware operation. Based on currently available intelligence, the group has no confirmed public research footprint, no documented tooling list, and no established victim count. This is significant from an assessment standpoint.

Many ransomware brands that appear with little to no track record fall into one of a few categories:

  • Rebrands or spin-offs of established operations seeking to evade law enforcement and researcher attention.
  • Low-maturity actors running leaked or purchased ransomware-as-a-service (RaaS) builds.
  • Attention-seeking or opportunistic actors who may exaggerate or fabricate claims to build notoriety.

Because threeam has no known tools, tactics, or procedures (TTPs) documented in public research, we cannot attribute specific techniques such as double extortion, data exfiltration methods, or initial access vectors to this group with any confidence. Analysts should treat any capability claims as unproven until corroborated.

No YARA rules or detection signatures specific to threeam are publicly available at this time. Defenders should rely on general ransomware detection guidance rather than actor-specific indicators.

Alleged Data Exposure

The threat actor’s listing describes Coosalud as one of Colombia’s major EPS organizations, managing subsidized and contributory healthcare regimes with multi-million-peso operating volumes. However, the group has not published a data volume, and no samples have been provided.

This absence matters. In many credible ransomware claims, operators publish at least a small proof set to pressure victims into paying. A listing with no evidence may indicate:

  • The data has not yet been uploaded or staged.
  • The claim is exaggerated or premature.
  • The actor is bluffing to extract payment.

We cannot confirm what data, if any, was allegedly accessed. No personally identifiable information (PII), credentials, or data samples are referenced or reproduced in this report, in line with our editorial policy.

Potential Impact

If the claim is accurate, a healthcare insurer in Colombia could face exposure of sensitive patient, claims, and enrollment data. Healthcare entities are attractive targets because of regulatory pressure and the operational criticality of their services.

Potential consequences could include regulatory scrutiny under Colombian data protection law, operational disruption, reputational harm, and downstream fraud risk for members. However, none of this is confirmed, and the actual scope remains unknown.

What to Watch For

  • Whether threeam publishes proof samples or a data volume in the coming days.
  • Any official statement from Coosalud or Colombian health authorities.
  • Whether the listing is removed, suggesting a payment or negotiation.
  • Any corroborating reporting from regional incident response firms.
  • Reuse of threeam infrastructure or leak site patterns by other emerging groups.

Disclaimer

This report is based solely on an unverified claim posted to a ransomware group’s leak site. Yazoul Security has not independently verified the existence, scope, or authenticity of any alleged data breach involving Coosalud. The threat actor’s statements should be treated with skepticism, as ransomware groups routinely exaggerate or fabricate claims to pressure victims. No PII, credentials, download links, or access instructions are included in this report. Readers should await official confirmation before drawing conclusions.

Share:

Never miss a threat intelligence alert

Get real-time security alerts delivered to your preferred platform.

Related Claims

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.