On August 14, 2025, the Brazilian hospital network Complexo Hospitalar de São Bernardo do Campo appeared on the LockBit 5 ransomware leak site with internal files listed for public download after the organization apparently refused to pay an extortion demand.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch chmsbc.org.br
Get alerted the next time chmsbc.org.br files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about chmsbc.org.br’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting indicates that attackers exfiltrated internal files from the hospital’s systems and published a sample on the LockBit 5 dark-web portal. The Complexo Hospitalar de São Bernardo do Campo, which includes the Hospital de Clínicas, provides care to a large patient population in the São Paulo metropolitan area. No exact victim count has been released, and the precise volume of stolen data remains unclear from available screenshots and postings. The listing follows the group’s standard pattern of first encrypting victim networks, then exfiltrating selected directories before threatening to publish them if ransom is not paid.
Industry research from sources such as DoxxScan™ continuous monitoring indicates that healthcare organizations continue to face elevated risk because medical records, insurance details, and staff credentials hold long-term resale value on criminal markets.
Why This Matters for You and Your Family
When a hospital’s internal files are stolen, the information often includes patient names, dates of birth, national ID numbers, addresses, phone numbers, email accounts, and sometimes treatment or insurance records. If your family has ever received care at facilities connected to Complexo Hospitalar de São Bernardo do Campo, those details may now sit in an attacker’s archive. Stolen healthcare data tends to circulate for years because it can be used to file fraudulent claims, open accounts in your name, or pressure you with embarrassing personal details.