Description:
ARS RENACER, S.A. DUMP: ANALYSIS OF A HEALTH INSURANCE COMPANY LEAK
═══════════════════════════════════════════════════
ARS Renacer, S.A. (Dominican Republic) is a private Health Risk Administrator (ARS), licensed by SISALRIL (Law 87-01). Member of ADIMARS. It serves hundreds of thousands of affiliates through 24 regional offices.
**DUMP VOLUME:** 274,404 files / 158,693 critical and high-risk files
▸ 50,894 files in the "Usuarios" (Users) folder — user accounts for all systems
▸ .ssh/ + .bash_history + .gitconfig — access keys and command history of IT personnel
▸ 4,501 files — direct affiliate databases (names, cédulas [national IDs], phone numbers, addresses)
▸ 3,000 backup files — potentially complete database dumps
▸ 679 files — employee payroll data
▸ 500 files — passwords and access tokens to financial systems
**MEDICAL DATA (PHI):**
▸ 19,443 medical service authorization files — diagnoses, procedures, patient names
▸ 13,928 pre-certification files
▸ 810 pre-certification files (treatment details)
▸ 199 medical record files (expediente clínico)
▸ 1,569 prescription files linked to diagnoses
▸ 252 claims files containing PHI
**FINANCIAL DATA:**
▸ 4,863 financial transaction files — payments, refunds, bank details
▸ 3,676 account files with affiliates' financial data
▸ 3,467 financial documents (reports, balance sheets, budgets)
▸ 1,293 files containing financial system secrets and tokens
**REGULATORY RISKS:**
▸ Law 172-13 (Personal Data Protection) — Article 13 directly violated; penalties: 6 months to 2 years in prison + fines up to 150 minimum wages per incident
▸ Law 42-01, Article 28 (Confidentiality of clinical records)
▸ Law 53-07 (Cybercrime) — mandatory DICAT investigation
▸ Circular SSRL-INT-2025-000827 SISALRIL — direct requirement to protect PHI
▸ Precedent: SISALRIL fine of 2.3 million DOP for 5 incidents (2021); the current leak is orders of magnitude larger
**OTHER RISKS:**
▸ Exploitation of the Traspaso Digital system (SISALRIL, 2025) for massive illegal transfers of affiliates using leaked credentials
▸ Blackmailing patients with the threat of disclosing diagnoses
▸ BEC (Business Email Compromise) attacks on management (Board of Directors' data is in the dump)
▸ Synthetic identity theft and fabrication of fake cédulas
▸ Mass Habeas Data lawsuits — will paralyze the legal department
The dump contains a complete cross-section of the medical insurance company: from server SSH keys to the diagnoses of hundreds of thousands of patients and affiliates' bank details. The data cannot be invalidated — a cédula and medical history are immutable.
Legal Disclaimer:
Ransomware.live does not engage in the acquisition, exfiltration, downloading, possession,
hosting, access, consultation, redistribution, or disclosure of unlawfully obtained data.
This platform indexes only publicly visible information posted by ransomware operators and
open web sources without accessing or obtaining the underlying stolen content.
The service is provided to support public awareness, legitimate research, and cyber-resilience.
No stolen personal or confidential data is collected or distributed via this site.