LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Eva Care Listed by thegentlemen Ransomware Group

HIGH severityUnverified claimHow we verify

Eva Care Listed by thegentlemen Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·August 10, 2026
Eva Care Listed by thegentlemen Ransomware Group

Occurred August 2026 · publicly disclosed August 10, 2026.

HIGH
Severity
August 10, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Eva Care has been listed by thegentlemen ransomware group, with the incident disclosed on August 10, 2026. The breach involves personal data of an undisclosed number of individuals; check the company’s site or contact support to determine whether your information is affected and to follow recommended next steps.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

On August 10, 2026, the ransomware group known as thegentlemen listed Eva Care on its leak site. The listing names the organization and presents it as a victim of an intrusion, but public detail remains limited. Eva Care has not publicly confirmed the incident as of writing, and no independent verification from regulators or breach indexes is reflected in the available record. The claim matters because Eva Care operates in post-acute healthcare, a sector that routinely handles sensitive personal and clinical information; if any data were taken, the potential impact on patients, families, and staff would be significant even while the scale and contents stay unconfirmed.

What is known so far is confined to the group's public listing and basic organizational background. Counts of people affected, methods of access, timelines beyond the listing date, and any inventory of files are not disclosed in the material provided. Readers should treat the episode as an unverified accusation until corroborated.

What the listing says

Thegentlemen has listed Eva Care on its leak site under a headline that identifies the organization and associates it with the group. The reported date for the listing is August 10, 2026. The listing itself does not, in the available facts, supply a figure for people affected, name specific data types, describe how access was supposedly obtained, or state a ransom demand. Those elements are undisclosed.

According to the listing's framing, Eva Care appears as a claimed target. No statement from the company confirming theft, encryption, or data exposure is included in the record. The listing therefore stands as the group's claim rather than an established inventory of events. Public detail on timing of any alleged intrusion, volume of material, or technical method is limited.

Who is thegentlemen?

Thegentlemen is a ransomware and extortion group that has operated by listing organizations on a dedicated leak site and threatening to publish material unless demands are met. Like other actors in this category, the group typically combines claims of network access with pressure tactics aimed at forcing payment or attention. Public reporting on the group has described a pattern of naming victims, sometimes releasing sample files, and using the threat of wider disclosure as leverage.

For this specific listing, the only claim tied directly to Eva Care is the appearance of the organization's name on the group's site on the reported date. No further statements attributed to thegentlemen about file counts, particular systems, or internal details at Eva Care appear in the facts. Any broader description of the group's usual tactics is background on the actor, not evidence that those tactics were used here.

Who is Eva Care?

Eva Care, also referenced in public profiles as Eva Care Group, is a healthcare provider focused on the post-acute care industry. It is headquartered in Los Angeles, California, and operates and manages a network of nursing homes and rehabilitation facilities. Public descriptions note more than 50 years of combined experience and a model that covers clinical, financial, operational, and environmental management intended to support patient care.

Organizations in this sector sit at the intersection of clinical services and long-term residential or rehabilitative support. They typically maintain records tied to residents, patients, families, clinicians, and business operations. A leak-site listing naming such a provider draws attention because the sector's ordinary holdings can include information that, if misused, affects medical privacy, identity security, and trust in care settings. That consequence follows from the nature of the work, not from any confirmed loss of data in this case.

The information in question

The facts state that data types named as exposed are not disclosed. The listing does not provide an inventory of files, categories, or records. It is therefore not possible to assert what, if anything, left Eva Care's control.

If files were taken from an organization of this kind, firms in the post-acute and nursing-home sector typically hold combinations of patient and resident identifiers, clinical notes, treatment and medication histories, insurance and billing details, emergency contacts, staff employment records, and operational or financial documents. Those categories are characteristic of the industry; they are not a confirmed description of any material associated with this listing. Exact contents remain unconfirmed, and the number of people potentially affected is unknown.

Why it matters

A leak-site listing creates practical uncertainty for anyone connected to Eva Care as a patient, resident, family member, employee, or partner. Even when a claim is unverified, the possibility that personal or clinical information could surface later leads people to monitor accounts, watch for targeted fraud, and tighten ordinary security habits. Healthcare-related data, if obtained by criminals, can be misused for identity theft, insurance fraud, or social-engineering attempts that reference real care details to appear legitimate.

For the organization, an unconfirmed listing still carries reputational and operational weight: stakeholders expect clarity, regulators may inquire, and internal teams often must investigate whether systems were touched. None of that establishes that an intrusion occurred or that any particular control failed. What the listing establishes is only that a named group has publicly associated Eva Care with its extortion activity. What it does not establish is the truth of the claim, the scope of any access, or the presence of specific records in unauthorized hands.

Conditional risk is the appropriate frame. If material related to individuals were later shown to have been taken, those individuals could face elevated phishing and fraud pressure. If nothing was taken, the main cost is residual anxiety and the time spent checking. Until confirmation or clear contradiction appears, measured caution is more useful than assumption either way.

What to do now

Because the incident is an unverified claim and no data types have been confirmed, steps should stay conditional and practical. Consider the following if you have a relationship with Eva Care or believe your information could be involved:

Eva Care has not publicly confirmed the incident as of writing. Readers who want an additional check can run a free exposure scan of their email address to see whether that address has already appeared in other known breach datasets. That scan does not prove or disprove this particular listing; it only helps surface prior exposures that may already be circulating.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyEva Care security record
84/100
DoxxScan™ · Low doxx risk
B- 76Above-average record

1 reported incident on record.

See Eva Care’s full breach history →
RelatedMore incidents at Eva Care

More recent breaches

AnMed Listed by thegentlemen Ransomware GroupAugust 10, 2026PharmaEssentia Listed by thegentlemen Ransomware GroupAugust 10, 2026Premier Pigs Listed by thegentlemen Ransomware GroupAugust 10, 2026AIMS Group Listed by thegentlemen Ransomware GroupAugust 10, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the Eva Care Listed by thegentlemen Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by thegentlemen — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram