LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Medswana Listed by killsec Ransomware Group

HIGH severityUnverified claimHow we verify

Medswana Listed by killsec Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·May 20, 2025
Medswana Listed by killsec Ransomware Group

Reported May 20, 2025.

HIGH
Severity
May 20, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Medswana was listed by the killsec ransomware group on May 20, 2025, after internal files were exfiltrated in a ransomware attack; the exact date of the intrusion has not been established. Individuals who may have data with Medswana should review any notifications and take steps to protect their information.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

People whose personal or professional details sit inside Medswana’s systems now face the practical possibility that those records have left the organisation’s control. When a ransomware group lists a company and claims to have taken internal files, the immediate concern for individuals is straightforward: sensitive information could be published, sold, or used for fraud, identity theft, or targeted scams. The number of people affected remains unknown, and the precise contents of the files have not been confirmed, yet the mere claim of exfiltration is enough to put anyone connected to Medswana on notice.

On 20 May 2025 Medswana appeared on the killsec ransomware leak site. The group states that it stole internal data during a ransomware attack. Beyond that listing and the assertion of theft, public detail is limited. No confirmed figures for records taken, no verified timeline of the intrusion, and no independent confirmation of the group’s claims have been released.

Inside the incident

What is publicly known is narrow. Medswana was listed by the killsec ransomware group on its leak site on 20 May 2025. The group claims to have exfiltrated internal files as part of a ransomware attack. No further technical details—such as the initial access method, the duration of the intrusion, the volume of data removed, or any ransom demand—have been disclosed in available reporting. The number of people whose information may be involved is listed as unknown. The incident is therefore characterised solely by the group’s own claim of having stolen internal data and by the appearance of Medswana’s name on the leak site. Whether the files have been released, sold, or remain solely in the group’s possession is unconfirmed.

Ransomware operations of this type typically involve encryption of systems combined with data theft, after which the operators threaten to publish the material if payment is not made. In this case the only established fact is the listing itself and the accompanying claim of exfiltration. No independent verification of the breach’s scale or success has been published.

The group behind it: killsec

killsec is a ransomware operation that follows the now-common double-extortion model: encrypting a victim’s systems while simultaneously copying data and threatening to leak it. The group maintains a public leak site where it names organisations it claims to have compromised and, in some cases, posts samples or full archives of stolen material. Like other actors in this space, killsec typically seeks payment in cryptocurrency and uses the threat of public exposure to increase pressure. Its listings are claims made by the group itself; they are not independently audited confirmations of every detail asserted.

Public reporting on killsec has described a pattern of opportunistic targeting across multiple sectors, with victims ranging from smaller enterprises to larger organisations. The group’s communications are usually terse, focused on the fact of the intrusion and the threat of data release rather than elaborate technical disclosures. In the present case the only statement attributed to killsec is the listing of Medswana and the claim that internal data was stolen. No additional statements specific to this victim have been reported.

Who is Medswana?

Public detail about Medswana itself is limited. The organisation’s name indicates a connection to medical or healthcare services, most likely operating in or serving Botswana or a related regional market. Organisations of this kind typically manage patient records, staff information, administrative files, billing data, and operational documents. Even when an entity is relatively small, the data it holds can be highly sensitive because it often includes health-related details, contact information, and identifiers that can be reused for fraud or social engineering.

A breach affecting a medical or healthcare-related organisation is consequential precisely because of the nature of the information such entities routinely process. Health data is long-lived and difficult to change; once exposed it can remain useful to criminals for years. Staff and contractor records may contain national identity numbers, banking details, or employment histories. The combination of personal and medical information raises the stakes for anyone whose details appear in the internal files the group claims to have taken.

What was likely exposed

The only data type named in connection with the incident is “internal files” said to have been exfiltrated in a ransomware attack. No inventory of those files, no sample documents, and no confirmation of specific categories such as patient records, employee data, financial documents, or correspondence have been published. Because the exact contents remain unconfirmed, it is not possible to state with certainty what was taken.

Organisations operating in the medical or healthcare sector typically hold a range of sensitive material: clinical notes, appointment and billing records, staff personnel files, supplier contracts, and internal communications. Any of these could fall under the broad description of “internal files.” Until independent verification or a more detailed disclosure appears, the precise nature of the material remains unknown. Readers should treat any subsequent claims of specific data types as unverified unless corroborated by the organisation or by forensic reporting.

Why it matters

For individuals, the practical risks are concrete. If personal identifiers, contact details, or health-related information were among the internal files, those records can be used to craft convincing phishing messages, open fraudulent accounts, or attempt medical-identity fraud. Even non-medical administrative data—addresses, phone numbers, employment status—can feed social-engineering attacks. Because the number of people affected is unknown, anyone who has interacted with Medswana as a patient, employee, contractor, or partner has reason to monitor for unusual activity.

For the organisation the consequences include potential regulatory scrutiny, notification obligations, reputational damage, and the operational cost of investigating and containing the incident. Ransomware events also disrupt day-to-day services, which in a healthcare-related setting can affect patient care and administrative continuity. The absence of confirmed scale does not remove these risks; it simply means the full extent is still undetermined.

If your data was in this claimed breach

Begin by treating the claim seriously even while details remain limited. Monitor bank and credit accounts for unexpected activity, enable multi-factor authentication on email and financial services, and be alert to phishing messages that reference Medswana or medical services. If you have received any communication purporting to come from the organisation about the incident, verify it through official channels rather than links or attachments in the message itself. Change passwords on accounts that may have used the same credentials elsewhere, and consider placing fraud alerts with credit bureaus if you believe identity documents could be involved.

Because the full scope of the data is unconfirmed, a practical next step is to check whether your email address has already appeared in known breach collections. Free exposure-scan tools allow you to enter an email address and see whether it surfaces in previously disclosed incident data; doing so provides an early indicator of whether your information is circulating. Continue to watch for official statements from Medswana and for any verified updates on what was taken. Until more is known, caution and routine monitoring remain the most useful responses.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyMedswana security record
87/100
DoxxScan™ · Low doxx risk
B 80Good record

1 reported incident on record.

See Medswana’s full breach history →

More recent breaches

Allure Clinics Listed by killsec Ransomware GroupSeptember 16, 2025AVA Senior Connect Listed by killsec Ransomware GroupSeptember 9, 2025Archer Health Listed by killsec Ransomware GroupSeptember 7, 2025Suiza Lab Listed by killsec Ransomware GroupSeptember 6, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the Medswana Listed by killsec Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by killsec — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram