nhbg.com.co Listed by lockbit3 Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
nhbg.com.co was listed by the LockBit3 ransomware group on 4 September 2024, with internal files confirmed as exfiltrated; the exact date of the intrusion remains unknown and the number of individuals affected has not been disclosed. Anyone who may have had data held by nhbg.com.co should check the organisation’s notices and consider protective steps such as changing passwords and monitoring accounts.
Ransomware groups continue to target healthcare providers worldwide, exploiting the sector’s reliance on continuous operations and sensitive patient records to pressure victims into paying. Against that backdrop, the appearance of a Colombian hospital on a well-known leak site in early September 2024 fits a pattern that has become familiar to security observers: an unverified claim of data theft, followed by the threat of public release.
On 4 September 2024 the ransomware group that styles itself lockbit3 listed nhbg.com.co, the online presence of Nuevo Hospital de Bocagrande, asserting that it had stolen internal files. The number of people affected remains unknown, and independent confirmation of the claim has not been published. What is known is limited to the group’s own statement and the basic identity of the organisation.
Inside the incident
Public reporting of the incident consists solely of the lockbit3 leak-site entry dated 4 September 2024. The group announced that it was “posting here the new company, Nuevo Hospital de Bocagrande,” and described the organisation as a high-level comprehensive health-care facility established in 2009. It further claimed that internal files had been exfiltrated in a ransomware attack. No technical details of the intrusion method, no timeline of the compromise, no volume of data, and no sample files have been released in open sources. The number of individuals whose information may have been involved is listed as unknown. At present the listing itself constitutes an unverified claim rather than a claimed breach.
Inside lockbit3
Lockbit3 is the latest iteration of a ransomware operation that has operated as a ransomware-as-a-service franchise for several years. Affiliates obtain access to victim networks, deploy the encryptor, and exfiltrate data before encryption; the core group then hosts the stolen material on a dedicated leak site and negotiates payment. The model has produced a high volume of listings across many industries, including healthcare. Typical tactics include phishing, exploitation of unpatched remote-access services, and the use of legitimate administrative tools to move laterally once inside a network. The group’s public communications routinely frame each new listing as proof of successful theft, yet those statements remain claims until corroborated by the victim or by independent forensic evidence. In this case the only public assertion is the leak-site entry naming Nuevo Hospital de Bocagrande.
Who is nhbg.com.co?
Nuevo Hospital de Bocagrande is a private hospital located in Cartagena, Colombia. According to the description carried on the lockbit3 site, it was founded in 2009 to provide comprehensive, high-level medical care. Hospitals of this type maintain electronic health records, laboratory results, imaging studies, billing and insurance data, staff personnel files, and operational documents. Because the facility serves patients who may travel from other regions and because it operates in a regulated health sector, any unauthorised disclosure of its internal files carries consequences that extend beyond the organisation itself. The domain nhbg.com.co is the hospital’s public web presence; the listing therefore links the claimed intrusion directly to a functioning medical centre rather than to a purely administrative entity.
The information in question
The only data category named in the available facts is “internal files exfiltrated in ransomware attack.” No further breakdown—patient records, financial ledgers, employee data, or technical documentation—has been supplied. Organisations of this kind typically hold medical histories, contact details, insurance identifiers, and administrative correspondence. Until the hospital or an independent investigator confirms the precise contents, those categories remain unconfirmed possibilities rather than established facts. The claim of exfiltration stands as an assertion by the ransomware group; the actual composition of any stolen material has not been verified in public sources.
What's at stake
For patients and staff, the primary risk is the potential exposure of personal and medical information that could be used for identity fraud, targeted phishing, or social-engineering attacks. Even if clinical records are not among the files, internal administrative documents can still reveal names, addresses, and financial details. For the hospital, the consequences include possible regulatory scrutiny under Colombian data-protection rules, disruption of clinical workflows if systems were encrypted, and the longer-term erosion of patient trust. Because the scale of the alleged theft remains unknown, the precise number of individuals who may need to take protective steps cannot yet be determined. The absence of Reported Details does not eliminate the need for vigilance; it simply means that any response must be based on caution rather than on a complete inventory of compromised records.
Were you affected?
If you have been a patient, employee, or contractor of Nuevo Hospital de Bocagrande, treat the lockbit3 claim as a prompt to review your own exposure rather than as definitive proof. Monitor bank and credit statements for unusual activity, enable multi-factor authentication on email and financial accounts, and be alert to unexpected messages that reference the hospital or request personal information. You can also run a free exposure scan of your email address against known breach data sets to check whether your credentials or contact details have already appeared in other incidents. Should the hospital issue an official notification, follow the guidance it provides; until then, the practical steps above remain the most reliable first measures available to individuals.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
lamejor.com.co Listed by lockbit3 Ransomware Groupahn.org Listed by lockbit3 Ransomware Grouptpgagedcare.com.au Listed by lockbit3 Ransomware Groupchcm.us Listed by lockbit3 Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the nhbg.com.co Listed by lockbit3 Ransomware Group →
Publicly posted by lockbit — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.