coosalud.com Listed by 3am Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
coosalud.com was listed by the 3am ransomware group on 28 September 2026. The group claims it holds data belonging to an undisclosed number of individuals; anyone who may have interacted with the site should check for unusual activity and consider changing credentials.
Ransomware crews continue to pressure organisations by posting names on leak sites before any independent verification, a pattern that has become routine across healthcare and other regulated sectors. Listings of this kind are public accusations, not audited incident reports, and they often appear with little supporting detail.
On September 28, 2026, the group known as 3am listed coosalud.com on its leak site. The listing refers to Coosalud EPS (Coosalud Entidad Promotora de Salud S.A.). As of writing, the company has not publicly confirmed the claim. Public detail is limited: the number of people affected is unknown, and the types of data allegedly involved are not disclosed. Readers should treat the claim as unverified until the organisation, a regulator, or another independent source confirms or denies it.
What the listing says
According to the listing, 3am has named coosalud.com among organisations it claims to have compromised. The reported summary identifies the entity as Coosalud EPS, a major health promotion entity in Colombia that manages subsidized and contributory healthcare regimes and handles multi-million-peso operating volumes. The same summary fragment notes publication status described as 0% and a low view count on the listing page; those figures come from the leak-site presentation itself and do not establish what, if anything, was taken or released.
Timing of any alleged intrusion, technical method, ransom demand, and scale are undisclosed in the available record. The listing does not provide a confirmed inventory of files or records. Nothing in the public facts confirms that data left the organisation’s systems or that any dump has been published in full.
Inside 3am
3am is a known ransomware operation that has appeared in public reporting as a group that encrypts systems, exfiltrates data, and threatens publication on a dedicated leak site to increase pressure. Like other extortion-focused actors, it typically relies on initial access through common enterprise weaknesses, followed by lateral movement and double-extortion messaging. Its leak site functions as a stage for naming alleged victims and signalling claimed progress toward data release.
Well-documented public coverage of 3am describes a commercial ransomware model rather than a single one-off campaign: affiliates or operators claim access, post victims, and use timed disclosure threats. That general pattern does not prove the accuracy of any single listing. For this case, the only incident-specific assertion in the facts is that the group has listed coosalud.com; additional claims about what happened inside Coosalud’s environment are not established in the record provided.
Who is coosalud.com?
Coosalud EPS operates in Colombia’s health-insurance and care-coordination landscape as an entidad promotora de salud. Entities of this type enrol members, manage contributory and subsidized regimes, coordinate provider networks, and process large volumes of administrative and clinical-related information. Because they sit between patients, employers, the state, and healthcare providers, they are high-value targets for criminals seeking bulk personal and health-adjacent data.
A credible incident affecting such an organisation would matter because members depend on continuous access to coverage information, authorisations, and claims handling. Even an unconfirmed leak-site claim can create uncertainty for affiliates, partners, and the public, which is why careful attribution—and waiting for official confirmation—matters as much as technical detail.
The information in question
The facts state that data types named as exposed are not disclosed. The listing’s marketing language is not a verified inventory. It is therefore not possible to state which fields, databases, or document sets were involved, or whether any were involved at all.
If files were taken from a health promotion entity of this kind, organisations in the sector typically hold identity and contact details, membership and plan information, claims and billing records, authorisation histories, and sometimes clinical or referral-related documentation needed to administer care. That is a description of sector norms, not a finding about this listing. Exact contents remain unconfirmed, and the number of people potentially affected is unknown.
The real-world impact
Impact depends entirely on whether the claim is accurate and on what, if anything, left controlled systems. If personal or health-administration data may have been exposed, affected individuals could face phishing and social-engineering attempts that reference real membership details, attempts to commit identity fraud, or misuse of contact and document information. Healthcare-adjacent records are especially useful to scammers because they sound authoritative when used in follow-up messages.
For the organisation, an extortion listing can mean operational distraction, reputational pressure, and engagement with insurers, regulators, and members—even when facts are still unsettled. A leak-site post alone does not establish negligence, successful exfiltration, or the sensitivity of any particular dataset. It establishes that a named group chose to publish an accusation and attach the company’s domain to its site.
Until confirmation exists, the responsible reading is conditional: monitor official channels from Coosalud EPS, treat unsolicited “breach assistance” messages with scepticism, and avoid assuming that any specific record about you is in criminal hands solely because a listing appeared.
What to do now
If you have a relationship with Coosalud EPS—as a member, employee, contractor, or partner—use official company or regulator channels for updates rather than leak-site screenshots or forwarded rumours. Practical steps if your information might be involved include the following:
- Be cautious with unexpected emails, calls, or messages that cite health-plan details, urgent payments, or “data recovery” services.
- Prefer unique passwords and multi-factor authentication on email and any portals tied to benefits or identity documents.
- Watch financial and government identity accounts for unfamiliar activity if you later learn that identity data was involved.
- Keep copies of any official notices you receive so you can compare them with scam lookalikes.
- Run a free exposure scan of your email to check whether your address has already appeared in known breach datasets unrelated or related to past incidents.
A listing by 3am is a claim, not a closed investigation. Public confirmation from the company remains absent as of writing, people affected are unknown, and data types are not disclosed. Conditional vigilance is warranted; treating the accusation as proven fact is not.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
SourceLeak-site claim data adapted from RansomLook.io, used under CC BY 4.0.
More recent breaches
stjames.wa.edu.au Listed by 3am Ransomware Groupbhn-expertise.com Listed by 3am Ransomware Groupapexus.com Listed by 3am Ransomware Groupsafescaffolding.net Listed by 3am Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the coosalud.com Listed by 3am Ransomware Group →
Publicly posted by 3am — unverified claim, pending independent verification. Leak-site claim data adapted from RansomLook.io, used under CC BY 4.0.
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.