Consorci Sanitari Integral & Geseme Listed by ransomexx Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The Consorci Sanitari Integral & Geseme Listed by ransomexx Ransomware Group (reported October 11, 2022) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
Healthcare organisations remain a persistent target in the ransomware economy, where attackers prize both operational disruption and the sensitivity of the data these bodies hold. Against that backdrop, Consorci Sanitari Integral & Geseme appeared on a ransomexx leak site in a listing reported on 11 October 2022, with the group claiming that internal files had been taken in a ransomware attack.
Public detail on the incident is limited. The number of people affected is unknown, and the precise scope of what was copied has not been independently confirmed. For patients, staff and partners of a Catalan public health consortium, even an unverified claim warrants clear, factual attention.
Breaking down the breach
According to available reporting, Consorci Sanitari Integral & Geseme was listed by the ransomexx ransomware group on or around 11 October 2022. The group’s claim centres on the exfiltration of internal files in the course of a ransomware attack. No confirmed figure for individuals affected has been published, and public sources do not disclose the initial access method, the duration of any intrusion, or whether systems were encrypted as well as data stolen.
The listing itself is an assertion by the threat actor. Independent verification of the volume, sensitivity or full contents of any taken material has not been supplied in the facts available. Timing beyond the October 2022 report date, and any subsequent negotiation or data release, remain undisclosed in public summaries of this incident.
Who is ransomexx?
Ransomexx is a documented ransomware operation that has targeted large organisations across multiple sectors. Public reporting over several years has associated the group with double-extortion tactics: encrypting systems where possible while also copying data and threatening to publish it if a ransom is not paid. The group has previously appeared under related names in industry tracking and has listed victims on dedicated leak sites to increase pressure.
Like other ransomware crews of its type, ransomexx typically seeks high-impact targets whose downtime or data exposure carries significant cost. Claims posted on such sites should be treated as assertions by the attackers unless corroborated by the victim organisation or independent investigation. In this case, the facts record only that Consorci Sanitari Integral & Geseme was listed and that internal files were described as exfiltrated; no further specific statements by the group about this victim are provided.
Who is Consorci Sanitari Integral & Geseme?
Consorci Sanitari Integral (CSI) is a public entity providing health and social services. It was formed in 2000, taking on former Red Cross hospitals in the province of Barcelona. It is participated in by the Catalan Health Service, the Catalan Institute of Health, the municipalities of L’Hospitalet de Llobregat and Sant Joan Despí, the Baix Llobregat county council, and the Red Cross. In 2016 Carles Constante i Beitia was appointed director general. Geseme appears alongside CSI in the breach reporting as part of the same organisational reference.
Bodies of this kind sit at the centre of regional care delivery. They routinely manage clinical records, administrative files, staff information and operational systems that support hospitals and related services. A ransomware claim against such an organisation is consequential because interruption of care systems and exposure of health-related data can affect both continuity of service and the privacy of large numbers of people, even when exact counts remain unknown.
What was likely exposed
The facts state that internal files were exfiltrated in a ransomware attack. No further breakdown of data types, file counts or named categories has been disclosed. Exact contents are therefore unconfirmed.
Organisations in the public healthcare and social-services sector typically hold material such as:
- Patient administrative and clinical records
- Staff and contractor personal and employment data
- Operational, financial and procurement documents
- Internal correspondence and system configuration information
Any of the above could fall under a broad description of “internal files,” but it would be inaccurate to assert that specific categories were taken in this incident. Readers should treat the exposure as limited to what the threat actor has claimed until official confirmation is available.
The real-world impact
For individuals, the primary risks associated with healthcare-related internal files include identity misuse, targeted phishing that leverages personal or medical context, and longer-term privacy harm if sensitive health or social-care details circulate. Because the number of people affected is unknown and the precise data types are unconfirmed, the scale of personal impact cannot be stated as fact.
For the organisation, a ransomware listing can mean operational strain, regulatory notification duties under European data-protection rules, reputational damage, and the cost of investigation and recovery. Public health consortia also face the practical challenge of maintaining care while systems are examined or restored. None of these outcomes prove negligence; they are the ordinary consequences that follow when attackers claim to have removed internal material from a complex care provider.
Were you affected?
If you are a patient, employee or partner of Consorci Sanitari Integral or Geseme, monitor official statements from the organisation and from Catalan health authorities. Watch financial and email accounts for unusual activity, and be cautious of unsolicited messages that reference health services or personal details. Consider placing fraud alerts with relevant agencies if you believe sensitive identifiers may have been involved. You can also run a free exposure scan of your email address to check whether your information has already appeared in known breach datasets, which may help you decide what further steps to take.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Consorci Sanitari Integral Listed by ransomexx Ransomware GroupUnimed Belem Listed by ransomexx Ransomware GroupDiagnostica Stago Listed by ransomexx Ransomware GroupGrupo Vargas Listed by ransomexx Ransomware GroupLatest breaches
Publicly posted by ransomexx — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.