LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Consorci Sanitari Integral & Geseme Listed by ransomexx Ransomware Group

HIGH severityUnverified claimHow we verify

Consorci Sanitari Integral & Geseme Listed by ransomexx Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·October 11, 2022
Consorci Sanitari Integral & Geseme Listed by ransomexx Ransomware Group

Reported October 11, 2022.

HIGH
Severity
October 11, 2022
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The Consorci Sanitari Integral & Geseme Listed by ransomexx Ransomware Group (reported October 11, 2022) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Healthcare organisations remain a persistent target in the ransomware economy, where attackers prize both operational disruption and the sensitivity of the data these bodies hold. Against that backdrop, Consorci Sanitari Integral & Geseme appeared on a ransomexx leak site in a listing reported on 11 October 2022, with the group claiming that internal files had been taken in a ransomware attack.

Public detail on the incident is limited. The number of people affected is unknown, and the precise scope of what was copied has not been independently confirmed. For patients, staff and partners of a Catalan public health consortium, even an unverified claim warrants clear, factual attention.

Breaking down the breach

According to available reporting, Consorci Sanitari Integral & Geseme was listed by the ransomexx ransomware group on or around 11 October 2022. The group’s claim centres on the exfiltration of internal files in the course of a ransomware attack. No confirmed figure for individuals affected has been published, and public sources do not disclose the initial access method, the duration of any intrusion, or whether systems were encrypted as well as data stolen.

The listing itself is an assertion by the threat actor. Independent verification of the volume, sensitivity or full contents of any taken material has not been supplied in the facts available. Timing beyond the October 2022 report date, and any subsequent negotiation or data release, remain undisclosed in public summaries of this incident.

Who is ransomexx?

Ransomexx is a documented ransomware operation that has targeted large organisations across multiple sectors. Public reporting over several years has associated the group with double-extortion tactics: encrypting systems where possible while also copying data and threatening to publish it if a ransom is not paid. The group has previously appeared under related names in industry tracking and has listed victims on dedicated leak sites to increase pressure.

Like other ransomware crews of its type, ransomexx typically seeks high-impact targets whose downtime or data exposure carries significant cost. Claims posted on such sites should be treated as assertions by the attackers unless corroborated by the victim organisation or independent investigation. In this case, the facts record only that Consorci Sanitari Integral & Geseme was listed and that internal files were described as exfiltrated; no further specific statements by the group about this victim are provided.

Who is Consorci Sanitari Integral & Geseme?

Consorci Sanitari Integral (CSI) is a public entity providing health and social services. It was formed in 2000, taking on former Red Cross hospitals in the province of Barcelona. It is participated in by the Catalan Health Service, the Catalan Institute of Health, the municipalities of L’Hospitalet de Llobregat and Sant Joan Despí, the Baix Llobregat county council, and the Red Cross. In 2016 Carles Constante i Beitia was appointed director general. Geseme appears alongside CSI in the breach reporting as part of the same organisational reference.

Bodies of this kind sit at the centre of regional care delivery. They routinely manage clinical records, administrative files, staff information and operational systems that support hospitals and related services. A ransomware claim against such an organisation is consequential because interruption of care systems and exposure of health-related data can affect both continuity of service and the privacy of large numbers of people, even when exact counts remain unknown.

What was likely exposed

The facts state that internal files were exfiltrated in a ransomware attack. No further breakdown of data types, file counts or named categories has been disclosed. Exact contents are therefore unconfirmed.

Organisations in the public healthcare and social-services sector typically hold material such as:

Any of the above could fall under a broad description of “internal files,” but it would be inaccurate to assert that specific categories were taken in this incident. Readers should treat the exposure as limited to what the threat actor has claimed until official confirmation is available.

The real-world impact

For individuals, the primary risks associated with healthcare-related internal files include identity misuse, targeted phishing that leverages personal or medical context, and longer-term privacy harm if sensitive health or social-care details circulate. Because the number of people affected is unknown and the precise data types are unconfirmed, the scale of personal impact cannot be stated as fact.

For the organisation, a ransomware listing can mean operational strain, regulatory notification duties under European data-protection rules, reputational damage, and the cost of investigation and recovery. Public health consortia also face the practical challenge of maintaining care while systems are examined or restored. None of these outcomes prove negligence; they are the ordinary consequences that follow when attackers claim to have removed internal material from a complex care provider.

Were you affected?

If you are a patient, employee or partner of Consorci Sanitari Integral or Geseme, monitor official statements from the organisation and from Catalan health authorities. Watch financial and email accounts for unusual activity, and be cautious of unsolicited messages that reference health services or personal details. Consider placing fraud alerts with relevant agencies if you believe sensitive identifiers may have been involved. You can also run a free exposure scan of your email address to check whether your information has already appeared in known breach datasets, which may help you decide what further steps to take.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyConsorci Sanitari Integral & Geseme security record
88/100
DoxxScan™ · Low doxx risk
B 83Good record

1 reported incident on record.

See Consorci Sanitari Integral & Geseme’s full breach history →

More recent breaches

Consorci Sanitari Integral Listed by ransomexx Ransomware GroupOctober 11, 2022Unimed Belem Listed by ransomexx Ransomware GroupOctober 19, 2022Diagnostica Stago Listed by ransomexx Ransomware GroupMarch 1, 2022Grupo Vargas Listed by ransomexx Ransomware GroupDecember 21, 2024

Latest breaches

Read GalaxyWarden’s full analysis of the Consorci Sanitari Integral & Geseme Listed by ransomexx Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by ransomexx — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram