Centromedicoenova Listed by cloak Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
On 30 January 2025 the ransomware group known as cloak listed Centromedicoenova, stating that internal files had been exfiltrated during an attack whose timing remains unknown. Individuals connected to the organisation should check any notices issued by Centromedicoenova and monitor their personal accounts for unusual activity.
Centromedicoenova, a medical organisation based in Spain, was listed by the ransomware group known as cloak on or around 30 January 2025. Public details indicate that the group claims to have exfiltrated internal files during a ransomware attack, with the volume described as under 100 GB. The number of people affected remains unknown, and further specifics about the incident have not been confirmed in available records.
This listing matters because medical organisations routinely handle sensitive personal and health-related information. Even when exact contents are unconfirmed, any unauthorised access to internal files raises practical concerns for patients, staff and the organisation itself about potential misuse of data that could surface later.
Inside the incident
According to the available record, Centromedicoenova appeared on the leak site associated with the cloak ransomware group, with the listing dated 30 January 2025. The entry notes the country as Spain and describes the material as public, with a size under 100 GB. The reported summary characterises the event as involving internal files exfiltrated in a ransomware attack. No further details on the precise timing of the intrusion, the initial access method, encryption status of systems, or any ransom demand have been disclosed in the public facts. The number of individuals potentially affected is listed as unknown. Views on the listing page were recorded at 69 at the time of the report, though this figure does not itself confirm the authenticity or completeness of the claimed data.
Because the information originates from a threat-actor listing, it should be treated as an unverified claim by the group rather than independently confirmed disclosure by the organisation or authorities. No additional technical indicators, such as specific file names, systems compromised, or timelines beyond the reporting date, appear in the available facts.
Who is cloak?
Cloak is a ransomware group that has been publicly documented as operating a double-extortion model: encrypting victim systems while also exfiltrating data and threatening to publish it on a dedicated leak site if demands are not met. Like many contemporary ransomware operations, the group typically lists victims with limited metadata such as organisation name, country, claimed data volume and a short description, then provides download links or previews once a countdown expires. Public reporting on cloak has noted its use of common ransomware tactics, including initial access through phishing, exploited vulnerabilities or compromised credentials, followed by lateral movement and data staging before encryption. The group has appeared in multiple open-source threat-intelligence summaries as one of the actors active in the ransomware ecosystem, though its exact size, structure and affiliations remain opaque.
In this case, the listing of Centromedicoenova is presented solely as a claim by the group. No independent verification of the exfiltration or the contents is contained in the facts provided, and readers should regard the leak-site entry as an assertion rather than established fact.
About Centromedicoenova
Centromedicoenova operates in the healthcare sector in Spain. Organisations of this type typically provide medical services, diagnostics or related care and therefore maintain records that can include patient identities, contact details, clinical histories, appointment data, billing information and staff records. Even routine administrative files often contain personally identifiable information and health-related data that are subject to strict privacy rules under Spanish and European regulations.
A ransomware incident involving a medical centre is consequential because healthcare providers sit at the intersection of personal privacy and operational continuity. Disruption can affect appointment systems, access to records needed for care, and public trust. The presence of internal files on a threat-actor site, even if the exact nature remains unconfirmed, therefore carries weight beyond a purely technical event.
What was likely exposed
The facts state that internal files were exfiltrated in a ransomware attack and that the claimed volume is under 100 GB. No more granular inventory—such as specific categories of patient data, employee records, financial documents or system backups—is named. Because the precise contents are not disclosed, it is not possible to state with certainty what was taken.
Organisations in the medical sector commonly hold patient demographic data, clinical notes, laboratory results, insurance or payment details, staff personnel files, internal correspondence and operational documents. Any of these could fall under the broad heading of “internal files.” Until an official statement or forensic confirmation is issued, however, the exact data types remain unconfirmed. The under-100 GB figure provides only a rough upper bound on volume and does not reveal sensitivity or completeness of the material.
The real-world impact
For individuals whose information may have been among the internal files, the primary risks are identity misuse, targeted phishing that references real medical or personal details, and longer-term privacy exposure if the data is sold or recirculated. Even partial records can enable social-engineering attacks that appear legitimate because they contain accurate fragments of a person’s history. For staff, exposure of internal documents could reveal employment details or credentials that facilitate further compromise.
For Centromedicoenova itself, the incident carries operational, regulatory and reputational consequences. Healthcare providers in Spain are subject to data-protection obligations; a claimed breach may trigger notification duties to authorities and affected individuals, potential investigations, and the need for remediation measures such as password resets, system hardening and patient communications. Continuity of care can also be affected if systems remain offline or if staff must divert time to incident response. Public listings by ransomware groups often generate media attention that can erode patient confidence even before full details are known.
Because the number of people affected is unknown and the data types are described only at a high level, the scale of individual harm cannot yet be quantified. The impact remains real but currently unmeasured.
Were you affected?
If you have been a patient, employee or contractor of Centromedicoenova, treat the listing as a signal to take basic protective steps. Monitor bank and credit accounts for unusual activity, be alert to unexpected emails or calls that reference medical or personal details, and consider changing passwords on any accounts that may have reused credentials associated with the organisation. Enable multi-factor authentication wherever it is available. If you receive official notification from Centromedicoenova or Spanish data-protection authorities, follow the guidance provided.
Readers can also run a free exposure scan of their email address to check whether that address has already appeared in known breach data sets. Such a check does not confirm or rule out involvement in this specific incident, but it can surface other exposures that warrant attention. Stay attentive to any future statements from the organisation or regulators for clearer information on what was actually taken and who may be affected.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
TuftsMedicine Listed by cloak Ransomware GroupNeovita.de Listed by cloak Ransomware GroupFitzpatrickhotels.com Listed by cloak Ransomware Group*****l*****.us Listed by cloak Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Centromedicoenova Listed by cloak Ransomware Group →
Publicly posted by cloak — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.