Qilin Tied to Sanatorio Modelo de Caseros
CronUp Ciberseguridad added Sanatorio Modelo de Caseros to a list of Qilin victims, with an attack date of 08-26-2026.
Qilin keeps appearing in victim lists tied to Sanatorio Modelo de Caseros on leak sites, and CronUp Ciberseguridad has now added it to its bulletin with an attack date of 08-26-2026. The reference remains a leak-site claim, with no public independent confirmation from the hospital or Argentine authorities.
Update September 2, 2026: CronUp Ciberseguridad added Sanatorio Modelo de Caseros to a list of victims published on leak sites and explicitly linked it to Qilin, with an attack date of 08-26-2026. The bulletin treats it as a leak-site claim, with no independent confirmation of an actual compromise.
Qilin added Sanatorio Modelo de Caseros, a private hospital in Greater Buenos Aires, to its leak site and claimed to have stolen internal data from the institution. The claim still has no public confirmation from the hospital or Argentine authorities, and several monitoring platforms continue to treat it as an incident under verification.
What is known about the listing?
The case appears linked to Qilin across several leak-site and ransomware trackers. MedRisk reported that the group added the hospital to its leak page and said internal data had been stolen, while GalaxyWarden logged the listing in an extortion context and noted that the organization had not publicly confirmed the incident when it published its coverage.
Ransomware.live also listed Sanatorio Modelo de Caseros as a Qilin victim, with discovery and an estimated attack date of August 26, 2026. That record also shows 2 compromised employees and 6 compromised users, although it does not provide independent validation of the incident.
What do the specialized aggregators show?
The available aggregators agree on the pairing between the hospital and Qilin, but differ in how much certainty or operational detail they show. Darkfield, through Orizon One, marks it as a data-leak case, with generic references to medical histories and patient data, although the visible documentation is limited.
Breach House indexes the episode as a ransomware attack against Sanatorio Modelo de Caseros, in the Healthcare/Pharma category, with 51 to 100 employees, Argentina as the country, and August 26, 2026 as the discovery and publication date. In that record, the Disclosed / Notified field is listed as not disclosed yet, which reinforces that there was no public notification by the time it was logged.
RecentBreaches was more cautious and classified it as an unconfirmed breach claim, with high severity. According to that site, its only basis was the extortion group’s leak-site listing, and it found no regulators, breach indexes, or named media outlets to corroborate it.
HookPhish and Hendry Adrian’s personal blog reproduced the case as if the hospital had already been hit. HookPhish placed it in the Healthcare sector, with the domain www.sanatoriomodelo.com.ar, Argentina as the region, and breach and discovery dates around 18:57Z on August 26, 2026, without providing independent evidence. Hendry Adrian, for his part, described critical file encryption and operational disruption, citing the leak site’s onion URL as the only technical source.
Ransomlook also added Sanatorio Modelo de Caseros to its recent-posts feed as a victim associated with Qilin, without adding more detail about impact or confirmation. Taken together, the records describe an extortion and leak case still under verification, not a closed attribution.
CronUp Ciberseguridad has now added the same case to its August 28, 2026 cybersecurity news feed and included it among the victims published on data-leak sites, still as a claim attributed to Qilin. That mention does not add independent evidence about the scale of the incident or change, by itself, the public verification status.
Sources
- Victim: Sanatorio Modelo de Caserosransomware.live· ransomware.live
- Ransom! Sanatorio Modelo de Caseros (AUG-2026)hendryadrian.com· Hendry Adrian
- Sanatorio Modelo de Caseros data breach — Qilin ransomware leak (2026)darkfield.orizon.one· Darkfield (Orizon One)
- Qilin gang claims Buenos Aires hospital breach on leak sitemedrisk.io· MedRisk
- Recent postsransomlook.io· Ransomlook
- Sanatorio Modelo de Caseros — QILIN Ransomware Attackbreach.house· Breach House
- Ransomware Group qilin Hits: Sanatorio Modelo de Caseroshookphish.com· HookPhish
- Sanatorio Modelo de Caserosbreachsense.com· BreachSense
- Feed De Noticias De Ciberseguridad [28/08/2026]cronup.com· CronUp Ciberseguridad
- Sanatorio Modelo de Caseros Listed by Qilin Ransomware Group | GalaxyWardengalaxywarden.com· GalaxyWarden
- Sanatorio Modelo de Caseros: Unconfirmed Breach Claims & DoxxScan™ Ratingrecentbreaches.com· RecentBreaches



