LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surface
Recent BreachesData breach tracker

Recent Breaches › eCare Platform Listed by CRPxO Ransomware Group

HIGH severityUnverified claimHow we verify

eCare Platform Listed by CRPxO Ransomware Group: What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·July 27, 2026
eCare Platform Listed by CRPxO Ransomware Group

Reported July 27, 2026.

HIGH
Severity
1
Data types exposed
July 27, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

eCare Platform has been listed by the CRPxO ransomware group, with internal files reported to have been exfiltrated in an attack disclosed on July 27, 2026. An undisclosed number of people may be affected; individuals should check for any direct notifications and review their account security.

Severity & verification
HIGH severityUnverified claim
Contact / identity PII exposed.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Was your email in the eCare Platform Listed by CRPxO Ransomware Group breach?
See every leak tied to your email — not just this one. 15-second check, no card, no account.

Healthcare and health-technology platforms remain high-value targets for ransomware operators, who increasingly pair encryption with data theft and public leak-site pressure. In that climate, any listing of a care-related platform deserves clear, limited reporting rather than speculation.

On July 27, 2026, eCare Platform was reported as listed by the CRPxO ransomware group. Public detail describes a ransomware attack in which internal files were exfiltrated, with a claimed data volume of 14.2 GB. How many people may be affected is unknown, and independent confirmation of the full scope has not been established in the available record.

What happened

According to the reported incident summary, eCare Platform—operating in the healthcare and technology sector—was listed in connection with a ransomware attack attributed to CRPxO. The facts state that internal files were exfiltrated and that the volume of data described as leaked is 14.2 GB. The number of people affected is unknown. Timing of the intrusion beyond the July 27, 2026 reporting date, the initial access method, and whether systems were encrypted or only data was stolen are not disclosed in the available record.

A leak-site listing is a claim by the threat actor. It should be treated as an unverified assertion unless and until the organisation or independent investigators confirm the details. No further technical indicators, ransom demands, or negotiated outcomes are included in the public facts provided for this incident.

The group behind it: CRPxO

CRPxO is presented in open reporting as a ransomware actor that follows the familiar double-extortion pattern used by many modern groups: gain access, move laterally, exfiltrate data, and then threaten or carry out publication on a dedicated leak site if payment is not made. Such groups typically rely on phishing, exposed remote services, stolen credentials, or vulnerable edge software, then deploy encryption and data-theft tooling once inside. Public descriptions of CRPxO-style operations emphasise pressure through naming victims and advertising stolen volume rather than detailed technical write-ups for every case.

For this incident specifically, the facts support only that CRPxO listed eCare Platform and that the group’s claim involves internal files and a stated 14.2 GB of leaked data. No verified quotes, screenshots, or additional victim-specific statements from the group beyond that listing framework are part of the record used here. Readers should separate the group’s claim from confirmed forensic findings.

About eCare Platform

eCare Platform is identified in the incident summary as operating at the intersection of healthcare and technology. Organisations in this category commonly provide digital tools that support clinical workflows, patient engagement, care coordination, or related administrative services. Even without a full public corporate profile in the breach facts, the sector context is clear: platforms that sit near care delivery often process or connect to sensitive operational and personal information.

A breach involving such a platform is consequential because trust in health-related technology depends on confidentiality and continuity. Disruption or exposure can affect not only the organisation’s operations and contracts but also patients, clinicians, and partner providers who rely on the service. The facts do not establish negligence or specific security failures; they establish that the organisation was named in a ransomware-related listing with claimed exfiltration of internal files.

What data was at risk

The available facts name the exposed material as internal files exfiltrated in a ransomware attack, with a reported leaked volume of 14.2 GB. They do not itemise file categories, database tables, or whether patient health information, employee records, credentials, or only corporate documents were included. People affected remain unknown.

Organisations in healthcare technology typically hold or process combinations of operational documents, configuration data, business correspondence, and—depending on product design—personal or health-related information. That general pattern does not confirm what was in the 14.2 GB claimed here. Exact contents are unconfirmed; only the high-level description of internal files and the stated volume appear in the reported summary.

What's at stake

For individuals, risk depends entirely on whether personal or health-related data was among the internal files. If it was, possible outcomes include unwanted contact, phishing that references real details, identity misuse, or embarrassment from exposure of sensitive care-related information. If the material was limited to corporate internals, direct consumer harm may be lower, while competitive and operational harm to the organisation may still be significant. Because the affected population size and data types are not fully disclosed, people connected to eCare Platform cannot yet rule themselves in or out with certainty.

For the organisation, stakes include regulatory scrutiny common to healthcare-adjacent entities, contractual obligations to partners, potential service disruption, and reputational damage from a public ransomware listing. Recovery costs, legal review, and hardened security controls often follow such events whether or not a ransom is paid. None of these outcomes are asserted as already proven in the facts; they are the concrete categories of impact that typically attach to incidents of this type.

What to do if you're exposed

If you use or have used eCare Platform, or if you work with it as staff or a partner, treat the listing as a reason for heightened caution until official notices clarify scope. Practical first steps include:

Public detail on this incident remains limited: reported July 27, 2026; sector healthcare and technology; claimed 14.2 GB of internal files; people affected unknown. Further clarity will depend on confirmation from the organisation or independent investigation, not on the ransomware group’s listing alone.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyeCare Platform security record
64/100
DoxxScan™ · Moderate doxx risk
B- 76Above-average record

1 reported incident on record.

See eCare Platform’s full breach history →

More recent breaches

ProSmile Family Dental Care Listed by CRPxO Ransomware GroupJuly 27, 2026American Hospice & Home Health Services (Ahhh Care) Listed by CRPxO Ransomware GroupJuly 27, 2026Leah Walker Orthodontics Listed by CRPxO Ransomware GroupJuly 27, 2026Elko Dental Specialists Listed by CRPxO Ransomware GroupJuly 27, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the eCare Platform Listed by CRPxO Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by crpxo — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram