CiberLATAMbywhalemate

Chile and Guatemala hospitals hit by ransomware

Direwolf posted Chile’s Hospital Clínico Universidad de Chile and Guatemala’s Incán. The Guatemala case disrupted radiotherapy for 194 patients.

Whalemate Labs · AI-assisted researchPublished:2 min read

Direwolf posted Chile’s Hospital Clínico Universidad de Chile on its leak site, while Guatemala’s Incán confirmed a cybersecurity incident that briefly affected Radiotherapy and cut off access to systems used for 194 cancer patients.

Direwolf has now been linked to two separate attacks against health institutions in Latin America. In Chile, several monitoring and analysis platforms reported that the group had listed Hospital Clínico Universidad de Chile on its leak site, with an alleged 240 GB data exfiltration. In Guatemala, the Instituto Nacional de Cancerología, or Incán, acknowledged an incident that hit its Radiotherapy department and temporarily disrupted key services for cancer patients.

What happened at Hospital Clínico Universidad de Chile?

Direwolf posted the hospital on its leak site, but as of publication there was no public confirmation from the institution or regulators about the incident. MedRisk.io said the case appeared at the same time as a Turkish hospital, with a discovery date of August 30, 2026 on RansomLook and Ransomware.live. GalaxyWarden said the group claimed to have stolen internal data, without specifying how many people may have been affected or which categories of information were compromised.

HookPhish attributed the attack to Hospital Clínico Universidad de Chile and dated it technically to August 30, 2026, with redclinica.cl as the target domain, health sector, and Chile as the region, though it provided no independent evidence beyond the leak site listings. Ransom-DB placed the hospital in Independencia, Santiago, and described it as a public university hospital and the main clinical teaching center of the University of Chile School of Medicine. Hackmanac said Direwolf claimed to have compromised medical records, customer data, clinical logs from 2023 through 2026, biopsy files, patient documents, GES admission records, master files, and clinical histories. It marked the case as "Pending verification" despite citing a 240 GB exposure.

Security Arsenal added that its dark web monitoring confirmed the publication of Hospital Clínico Universidad de Chile among three new Direwolf victims in a 24-hour window, with two hospitals among those targets. Dexpose also said Direwolf claimed to have hit the hospital and warned of a possible data leak if no negotiation took place. TweetThreatNews reported hospital operations disruption and encrypted data, but did not add official support or technical details.

What did Incán confirm in Guatemala?

The Instituto Nacional de Cancerología, Incán, confirmed that its Radiotherapy department was breached in a cybersecurity incident that temporarily affected its services. The official communication came after questions from La Hora, which had cited internal sources about system outages and loss of access to previous MRI records, affecting patient follow-up.

La Hora also reported that the attack encrypted the system used to plan radiotherapy and temporarily affected about 194 patients. Later, the Liga Nacional contra el Cáncer, the entity responsible for Incán, said the case was under investigation by the relevant authorities and that administrative, medical, physics, and technical teams were working to restore care while prioritizing patient safety.

Infobae later expanded on the scope, saying the incident temporarily cut off access to the system containing radiotherapy treatment plans, doses, and clinical images, affected 194 cancer patients, and forced the suspension of radiotherapy, brachytherapy, and superficial radiotherapy. The same coverage said the linear accelerators were not compromised and that in-person medical consultations continued to operate.

Sources

View all