Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Enjoying ransomware.live? Help us keep tracking ransomware gangs and shipping new features. Support us

arsrenacer.com

arsrenacer.com

Discovered 2026-09-20 20:58 UTC
Est. attack date 2026-09-01
Country AR
Sector
Agriculture and Food Production Education Energy & Utilities Financial Services Government & Defense Healthcare Hospitality Manufacturing Other Professional Services Retail & E-Commerce Technology Transportation

Description:

ARS RENACER, S.A. DUMP: ANALYSIS OF A HEALTH INSURANCE COMPANY LEAK ═══════════════════════════════════════════════════ ARS Renacer, S.A. (Dominican Republic) is a private Health Risk Administrator (ARS), licensed by SISALRIL (Law 87-01). Member of ADIMARS. It serves hundreds of thousands of affiliates through 24 regional offices. **DUMP VOLUME:** 274,404 files / 158,693 critical and high-risk files ▸ 50,894 files in the "Usuarios" (Users) folder — user accounts for all systems ▸ .ssh/ + .bash_history + .gitconfig — access keys and command history of IT personnel ▸ 4,501 files — direct affiliate databases (names, cédulas [national IDs], phone numbers, addresses) ▸ 3,000 backup files — potentially complete database dumps ▸ 679 files — employee payroll data ▸ 500 files — passwords and access tokens to financial systems **MEDICAL DATA (PHI):** ▸ 19,443 medical service authorization files — diagnoses, procedures, patient names ▸ 13,928 pre-certification files ▸ 810 pre-certification files (treatment details) ▸ 199 medical record files (expediente clínico) ▸ 1,569 prescription files linked to diagnoses ▸ 252 claims files containing PHI **FINANCIAL DATA:** ▸ 4,863 financial transaction files — payments, refunds, bank details ▸ 3,676 account files with affiliates' financial data ▸ 3,467 financial documents (reports, balance sheets, budgets) ▸ 1,293 files containing financial system secrets and tokens **REGULATORY RISKS:** ▸ Law 172-13 (Personal Data Protection) — Article 13 directly violated; penalties: 6 months to 2 years in prison + fines up to 150 minimum wages per incident ▸ Law 42-01, Article 28 (Confidentiality of clinical records) ▸ Law 53-07 (Cybercrime) — mandatory DICAT investigation ▸ Circular SSRL-INT-2025-000827 SISALRIL — direct requirement to protect PHI ▸ Precedent: SISALRIL fine of 2.3 million DOP for 5 incidents (2021); the current leak is orders of magnitude larger **OTHER RISKS:** ▸ Exploitation of the Traspaso Digital system (SISALRIL, 2025) for massive illegal transfers of affiliates using leaked credentials ▸ Blackmailing patients with the threat of disclosing diagnoses ▸ BEC (Business Email Compromise) attacks on management (Board of Directors' data is in the dump) ▸ Synthetic identity theft and fabrication of fake cédulas ▸ Mass Habeas Data lawsuits — will paralyze the legal department The dump contains a complete cross-section of the medical insurance company: from server SSH keys to the diagnoses of hundreds of thousands of patients and affiliates' bank details. The data cannot be invalidated — a cédula and medical history are immutable.

Infostealer activity detected by HudsonRock

Compromised Employees: 1

Compromised Users: 15

Third Party Employee Credentials: 3


External Attack Surface: 6


Exposure Report
by ParanoidLab
200
Passwords
35 critical
10
Cookies
0 critical
Last queried 2026-09-20 20:57 UTC


Leak Screenshot:

Leak Screenshot