LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › coosalud.com Listed by 3am Ransomware Group

HIGH severityUnverified claimHow we verify

coosalud.com Listed by 3am Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·September 28, 2026
coosalud.com Listed by 3am Ransomware Group

Reported September 28, 2026.

HIGH
Severity
September 28, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

coosalud.com was listed by the 3am ransomware group on 28 September 2026. The group claims it holds data belonging to an undisclosed number of individuals; anyone who may have interacted with the site should check for unusual activity and consider changing credentials.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Ransomware crews continue to pressure organisations by posting names on leak sites before any independent verification, a pattern that has become routine across healthcare and other regulated sectors. Listings of this kind are public accusations, not audited incident reports, and they often appear with little supporting detail.

On September 28, 2026, the group known as 3am listed coosalud.com on its leak site. The listing refers to Coosalud EPS (Coosalud Entidad Promotora de Salud S.A.). As of writing, the company has not publicly confirmed the claim. Public detail is limited: the number of people affected is unknown, and the types of data allegedly involved are not disclosed. Readers should treat the claim as unverified until the organisation, a regulator, or another independent source confirms or denies it.

What the listing says

According to the listing, 3am has named coosalud.com among organisations it claims to have compromised. The reported summary identifies the entity as Coosalud EPS, a major health promotion entity in Colombia that manages subsidized and contributory healthcare regimes and handles multi-million-peso operating volumes. The same summary fragment notes publication status described as 0% and a low view count on the listing page; those figures come from the leak-site presentation itself and do not establish what, if anything, was taken or released.

Timing of any alleged intrusion, technical method, ransom demand, and scale are undisclosed in the available record. The listing does not provide a confirmed inventory of files or records. Nothing in the public facts confirms that data left the organisation’s systems or that any dump has been published in full.

Inside 3am

3am is a known ransomware operation that has appeared in public reporting as a group that encrypts systems, exfiltrates data, and threatens publication on a dedicated leak site to increase pressure. Like other extortion-focused actors, it typically relies on initial access through common enterprise weaknesses, followed by lateral movement and double-extortion messaging. Its leak site functions as a stage for naming alleged victims and signalling claimed progress toward data release.

Well-documented public coverage of 3am describes a commercial ransomware model rather than a single one-off campaign: affiliates or operators claim access, post victims, and use timed disclosure threats. That general pattern does not prove the accuracy of any single listing. For this case, the only incident-specific assertion in the facts is that the group has listed coosalud.com; additional claims about what happened inside Coosalud’s environment are not established in the record provided.

Who is coosalud.com?

Coosalud EPS operates in Colombia’s health-insurance and care-coordination landscape as an entidad promotora de salud. Entities of this type enrol members, manage contributory and subsidized regimes, coordinate provider networks, and process large volumes of administrative and clinical-related information. Because they sit between patients, employers, the state, and healthcare providers, they are high-value targets for criminals seeking bulk personal and health-adjacent data.

A credible incident affecting such an organisation would matter because members depend on continuous access to coverage information, authorisations, and claims handling. Even an unconfirmed leak-site claim can create uncertainty for affiliates, partners, and the public, which is why careful attribution—and waiting for official confirmation—matters as much as technical detail.

The information in question

The facts state that data types named as exposed are not disclosed. The listing’s marketing language is not a verified inventory. It is therefore not possible to state which fields, databases, or document sets were involved, or whether any were involved at all.

If files were taken from a health promotion entity of this kind, organisations in the sector typically hold identity and contact details, membership and plan information, claims and billing records, authorisation histories, and sometimes clinical or referral-related documentation needed to administer care. That is a description of sector norms, not a finding about this listing. Exact contents remain unconfirmed, and the number of people potentially affected is unknown.

The real-world impact

Impact depends entirely on whether the claim is accurate and on what, if anything, left controlled systems. If personal or health-administration data may have been exposed, affected individuals could face phishing and social-engineering attempts that reference real membership details, attempts to commit identity fraud, or misuse of contact and document information. Healthcare-adjacent records are especially useful to scammers because they sound authoritative when used in follow-up messages.

For the organisation, an extortion listing can mean operational distraction, reputational pressure, and engagement with insurers, regulators, and members—even when facts are still unsettled. A leak-site post alone does not establish negligence, successful exfiltration, or the sensitivity of any particular dataset. It establishes that a named group chose to publish an accusation and attach the company’s domain to its site.

Until confirmation exists, the responsible reading is conditional: monitor official channels from Coosalud EPS, treat unsolicited “breach assistance” messages with scepticism, and avoid assuming that any specific record about you is in criminal hands solely because a listing appeared.

What to do now

If you have a relationship with Coosalud EPS—as a member, employee, contractor, or partner—use official company or regulator channels for updates rather than leak-site screenshots or forwarded rumours. Practical steps if your information might be involved include the following:

A listing by 3am is a claim, not a closed investigation. Public confirmation from the company remains absent as of writing, people affected are unknown, and data types are not disclosed. Conditional vigilance is warranted; treating the accusation as proven fact is not.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

SourceLeak-site claim data adapted from RansomLook.io, used under CC BY 4.0.

Companycoosalud.com security record
84/100
DoxxScan™ · Low doxx risk
B- 76Above-average record

1 reported incident on record.

See coosalud.com’s full breach history →

More recent breaches

stjames.wa.edu.au Listed by 3am Ransomware GroupSeptember 28, 2026bhn-expertise.com Listed by 3am Ransomware GroupSeptember 28, 2026apexus.com Listed by 3am Ransomware GroupSeptember 28, 2026safescaffolding.net Listed by 3am Ransomware GroupSeptember 28, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the coosalud.com Listed by 3am Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by 3am — unverified claim, pending independent verification. Leak-site claim data adapted from RansomLook.io, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram