Critical Unverified

Hospital de Sant Pau Ransomware Claim by thegentlemen (Oct 2026)

By Yazoul AI · automated

Unverified dark web claim. This report is based on a post observed on a dark web forum. Yazoul Security has not independently verified the authenticity of this claim.

Claim Summary

The ransomware group known as “thegentlemen” has allegedly listed Hospital de la Santa Creu i Sant Pau, a historic Barcelona healthcare and research institution, on its dark web leak site. According to the threat actor, the attack was purportedly carried out on October 2, 2026. The group claims to have exfiltrated data from the organization, though the total volume of allegedly stolen information remains undisclosed.

This claim has NOT been independently verified. It is a single unconfirmed assertion published by a criminal group with a clear incentive to exaggerate. Readers should treat every detail below as unproven until the hospital or Spanish authorities confirm otherwise.

Threat Actor Profile

thegentlemen is a ransomware operation that has drawn attention in 2025 and 2026 for aggressive double extortion tactics. Publicly available research on the group remains limited, and its total number of confirmed victims is unknown. No reliable tooling fingerprint has been published, so we cannot attribute specific malware families, initial access vectors, or exfiltration utilities to this actor with confidence.

What is generally observed across groups using this branding is a pattern of data theft followed by public leak site pressure. Because the group’s known tools and tactics are not documented in open sources, defenders should avoid assuming a specific intrusion method. The absence of public research also means detection engineering for this actor is largely generic rather than signature based. Organizations should rely on behavioral detection - unusual data staging, large outbound transfers, and abnormal authentication patterns - rather than actor-specific YARA rules, none of which are currently available for this group.

Alleged Data Exposure

The leak site entry references the hospital’s domain and a third-party business intelligence profile page. It does not specify data categories, record counts, or file types. The group has not published samples, and we will not reproduce any leaked material here.

The victim is a large institution. According to public information, the hospital employs roughly 4,965 people, operates on an annual budget near 490 million euros, and serves more than 400,000 patients a year. Its research institute reportedly employs over 1,600 staff and runs hundreds of active clinical trials. If the claim is accurate, the potential sensitivity of healthcare, research, and patient-adjacent data would be significant. However, no evidence has been provided to substantiate the scope.

Potential Impact

Healthcare providers face elevated risk from ransomware because downtime can affect patient care. A confirmed incident could disrupt clinical systems, appointment scheduling, and research operations. Regulatory exposure under GDPR is also a consideration for an EU-based hospital if personal data were involved.

That said, this remains an allegation. Ransomware groups frequently inflate victim lists, recycle old claims, or list organizations they failed to fully compromise. There is no confirmation that data was actually taken, that systems were encrypted, or that the hospital experienced any operational disruption.

What to Watch For

  • Official statements from Hospital de Sant Pau or Catalan health authorities.
  • Any notification from Spanish data protection authorities (AEPD).
  • Updates to the leak site, including countdown timers or sample postings.
  • Whether the group publishes verifiable proof, which it has not done so far.
  • Independent reporting that corroborates the timeline or scope.

Until then, treat this as an unverified claim. For related tracking, see our intel coverage.

Disclaimer

This report is based solely on an unverified claim published by a ransomware group. Yazoul Security has NOT independently confirmed the attack, the data theft, or any details described above. The information is provided for situational awareness only. No leaked data, credentials, samples, or access instructions are included, and none will be provided. Organizations should verify through official channels before acting.

Share:

Never miss a threat intelligence alert

Get real-time security alerts delivered to your preferred platform.

Related Claims

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.