LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › www.drwilliansegalin.com.br Listed by qiulong Ransomware Group

HIGH severityUnverified claimHow we verify

www.drwilliansegalin.com.br Listed by qiulong Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·April 23, 2024
www.drwilliansegalin.com.br Listed by qiulong Ransomware Group

Reported April 23, 2024.

HIGH
Severity
April 23, 2024
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The www.drwilliansegalin.com.br Listed by qiulong Ransomware Group (reported April 23, 2024) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Patients and others who have dealt with a plastic-surgery practice may find that personal and medical information has been put at risk when a ransomware group claims to have taken internal files. On 23 April 2024 the website www.drwilliansegalin.com.br was listed by the qiulong ransomware group, which stated that it had exfiltrated internal files. The number of people affected remains unknown, and public detail on the exact contents is limited, yet the listing itself raises immediate practical concerns for anyone whose records may have been held by the practice.

Because medical and aesthetic-surgery providers routinely store sensitive personal data, even an unverified claim of exfiltration can leave individuals unsure whether their information is now circulating or being used for further harm. This article sets out only what has been reported, without speculation.

Breaking down the breach

According to the available record, www.drwilliansegalin.com.br was listed by the qiulong ransomware group on 23 April 2024. The group claimed that internal files had been exfiltrated in a ransomware attack. No confirmed figure for the number of people affected has been published, and the precise method of intrusion, the volume of data taken, and any ransom demand remain undisclosed in the public facts. The listing itself constitutes the group’s assertion rather than an independently verified confirmation of the full scope of the incident.

The reported summary accompanying the listing includes statements directed at the practitioner, describing him as a plastic surgeon operating in Passo Fundo, Frederico Westphalen and Serafina Corrêa and focusing on aesthetic, reconstructive and hair-implant procedures. Those remarks form part of the group’s public claim and are not independently corroborated here. Beyond the assertion that internal files were taken, further technical or operational details of the breach have not been released.

Who is qiulong?

qiulong is a ransomware group known for double-extortion tactics: encrypting systems while also claiming to steal data and threatening to publish it if payment is not made. Like many such actors, it maintains a leak site on which it lists organisations it says it has compromised, often posting samples or full archives after a period of pressure. Public reporting on the group has documented a pattern of targeting a range of sectors and of using standard ransomware tooling combined with data-exfiltration stages. Its listings are claims made by the group itself; they do not automatically establish that every detail asserted about a particular victim is accurate.

In the present case the group has listed www.drwilliansegalin.com.br and stated that internal files were exfiltrated. No additional specific claims about this victim beyond that listing and the accompanying summary text appear in the facts provided. Readers should therefore treat the group’s statements as unverified assertions pending any independent confirmation.

www.drwilliansegalin.com.br and its sector

www.drwilliansegalin.com.br is the online presence of a plastic-surgery practice associated with Dr. Willian Segalin. Public information indicates that the practitioner works as a plastic surgeon in the Brazilian municipalities of Passo Fundo, Frederico Westphalen and Serafina Corrêa, offering aesthetic surgery, reconstructive procedures and hair implants. Practices of this kind typically maintain patient records, appointment histories, clinical notes, photographs, billing information and contact details.

A breach affecting such a provider is consequential because the data held is often highly personal and medical in nature. Even when the precise files taken remain unconfirmed, the mere possibility that clinical or identity-related records have left the organisation’s control creates lasting uncertainty for patients and can damage trust in the practice itself. The sector is not immune to ransomware; medical and aesthetic providers have repeatedly appeared on leak sites precisely because the sensitivity of their data increases the pressure to pay.

What data was at risk

The facts state that internal files were exfiltrated in a ransomware attack. No further breakdown of those files—such as specific categories of patient records, financial data or staff information—has been disclosed. The number of individuals whose data may be involved is listed as unknown.

Organisations of this type commonly hold names, addresses, telephone numbers, dates of birth, medical histories, procedure details, before-and-after images, insurance or payment information and correspondence. Whether any or all of those categories were among the internal files claimed by qiulong cannot be confirmed from the available record. The exact contents therefore remain unconfirmed, and any assumption about particular data types would be speculative.

Why it matters

For individuals, the practical risks include identity theft, targeted phishing that references real medical details, reputational harm if clinical photographs or notes become public, and long-term anxiety about residual exposure. Even if the files are never released, the fact that they may have been copied means they could later surface on criminal markets or be used in secondary attacks. For the practice, the consequences include potential regulatory scrutiny, loss of patient confidence, operational disruption from the ransomware itself, and the cost of investigation and remediation—none of which can be quantified from the public facts alone.

Because the scale remains unknown, it is impossible to say how many people face these risks. The absence of confirmed numbers does not reduce the seriousness of the claim; it simply leaves affected parties without clear information on which to act.

If your data was in this claimed breach

Anyone who has been a patient or otherwise shared personal information with the practice should treat the possibility of exposure seriously. Begin by monitoring financial accounts and credit reports for unusual activity, enable multi-factor authentication on email and other important accounts, and be alert to phishing messages that appear to reference medical or personal details. Consider placing a fraud alert with credit bureaux if you are concerned about identity misuse. Change passwords that may have been reused across services, and keep records of any suspicious contacts.

Public detail on this incident is limited, so definitive confirmation that a particular person’s data was taken is not yet available. Readers can run a free exposure scan of their email address to check whether that address has already appeared in known breach data sets; such a check provides one additional data point but cannot rule out every form of exposure. If you believe you have been affected, document any communications you receive and consider consulting local data-protection or consumer-protection resources for further guidance.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

Companywww.drwilliansegalin.com.br security record
88/100
DoxxScan™ · Low doxx risk
B 83Good record

1 reported incident on record.

See www.drwilliansegalin.com.br’s full breach history →

More recent breaches

hospitalescultural.com.br Listed by qiulong Ransomware GroupApril 26, 2024hominemclinic.com.br Listed by qiulong Ransomware GroupApril 24, 2024draandrearechia.com.br Listed by qiulong Ransomware GroupApril 22, 2024www.drlincoln.com.br Listed by qiulong Ransomware GroupApril 19, 2024

Latest breaches

Read GalaxyWarden’s full analysis of the www.drwilliansegalin.com.br Listed by qiulong Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by qiulong — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram