On April 19, 2024, the Brazilian plastic surgery clinic www.drlincoln.com.br, operated by Dr. Lincoln Graça Neto in Curitiba’s Batel neighborhood, appeared on the leak site of the qiulong ransomware group. Patients who visited the clinic for consultations, examinations, or surgical procedures now face the confirmed risk that their internal files have been exfiltrated.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 582 companies.
See what is exposed about you — free scan →Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.
Reported Details from the Listing
The qiulong leak site states that internal files were taken during a ransomware attack on the clinic. The disclosure does not quantify how many patient records were affected, nor does it list specific data types such as names, addresses, medical histories, photographs, or payment details. It simply states that exfiltrated material from drlincoln.com.br is now publicly listed. The business email contato@drlincoln.com.br and the physical address in Curitiba are also displayed alongside the samples. No ransom demand figure or payment deadline is shown in the current listing.
Why This Matters for You and Your Family
If you or any member of your family has been a patient at Dr. Lincoln’s clinic, your sensitive health and personal information may now sit in an attacker’s archive. Plastic surgery records frequently contain pre- and post-operative photographs, exact dates of procedures, financial transactions, and contact details that can be used for identity theft, insurance fraud, or targeted harassment. Because the leak site makes samples available, opportunistic criminals can begin searching the data immediately. Even if the full dataset has not yet been published, the mere confirmation of successful exfiltration changes your risk profile from theoretical to active.
The Doxxing and Identity-Chain Risk
Medical breaches like this one rarely stop at a single dataset. Attackers routinely cross-reference leaked patient emails, phone numbers, and addresses with credential-stuffing results from other breaches. A password reused from an old account can give them access to your email, which then reveals social-media handles, children’s names, and gaming usernames. Once those links are established, full doxxing chains form quickly. Public records, property deeds, and family photographs become easy to locate. For families with teenagers who maintain gaming accounts tied to the same email domain or phone number used at the clinic, the exposure can cascade into account takeovers and real-world stalking.