On March 18, 2024, the LockBit3 ransomware group listed Unimed.coop.br on its leak site, claiming that internal files had been exfiltrated from the Brazilian health insurance cooperative during a ransomware attack. The disclosure directly affects anyone who has received care through Unimed, used its insurance services, or had personal information processed by the organization, which serves more than 15 million beneficiaries across Brazil.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch unimed.coop.br
Get alerted the next time unimed.coop.br files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about unimed.coop.br’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Details from the Leak-Site Listing
The LockBit3 leak page states that Unimed suffered a ransomware intrusion and that attackers successfully exfiltrated internal files. The listing does not quantify the number of affected records, nor does it specify the exact types of data taken beyond the general description of internal files. No sample data appears to have been published at the time of the initial listing, and the disclosure provides no technical details about the initial access vector or the precise date of compromise. The primary source remains the LockBit3 onion site, mirrored on ransomware tracking platforms such as ransomware.live.
Why This Matters for You and Your Family
Health insurance and medical cooperative records typically contain names, dates of birth, national identification numbers, addresses, phone numbers, policy details, and clinical information. When such data leaves a protected environment, the exposure risk is immediate and long-lasting. If your family has used Unimed services, your personal and medical details may now sit in an attacker-controlled archive. This kind of breach cannot be undone; once exfiltrated, the information can be traded, sold, or used years later to commit identity theft, file fraudulent claims, or target family members with phishing campaigns that appear legitimate because they reference real medical history.
The Doxxing and Identity-Chain Risks
Medical data leaks create powerful anchor points for doxxing chains. A single exposed email or phone number linked to a health policy can be correlated with gaming accounts, social-media handles, and family addresses. Attackers routinely combine these fragments to build complete identity profiles. Children’s gaming accounts are especially vulnerable because parents often reuse passwords or security questions tied to family medical or insurance records. The result is a cascading exposure that can affect every member of a household long after the initial breach is forgotten.