On May 20, 2026, the Indonesian eye-care provider JEC Eye Hospitals and Clinics appeared on the LockBit 5 ransomware leak site with internal files listed for public download after the group claimed to have exfiltrated company data.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch jec.co.id
Get alerted the next time jec.co.id files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about jec.co.id’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting indicates that LockBit 5 added JEC Eye Hospitals and Clinics to its leak portal on that date. The posted material consists of internal files obtained during a ransomware intrusion. No confirmed total number of patient or employee records has been published, and the precise volume of data remains unclear from available screenshots and descriptions on the leak site. The hospital chain operates multiple locations across Indonesia and is known for advanced ophthalmic services. Ransomware.live, which monitors leak portals, recorded the listing on the LockBit 5 onion address.
Why This Matters for You and Your Family
When a healthcare provider’s internal files are stolen, the information inside often includes names, addresses, phone numbers, dates of birth, national ID numbers, medical histories, insurance details, and sometimes payment records. Any of these can be used to impersonate you, file fraudulent claims, open accounts in your name, or sell your details on underground markets. If you or a member of your family has ever visited JEC Eye Hospitals and Clinics, your personal health and contact data may now sit in an attacker’s archive. Medical data is especially damaging because it is difficult to change and can be leveraged for blackmail or identity theft years later.
The Doxxing and Identity-Chain Implications
A single breach rarely stops at one dataset. Attackers combine leaked emails, phone numbers, and patient IDs with information from other sources to build a complete profile—linking your clinic visits to social-media accounts, children’s school records, or online shopping profiles. This identity chain makes doxxing faster and more accurate. Credential leaks from healthcare systems frequently cascade into gaming platforms because families often reuse passwords or security questions. A child’s Roblox or Minecraft account tied to the same email can be taken over within hours of the credentials appearing for sale, exposing chat logs, payment methods, and location data that further enrich the attacker’s dossier.