Caja De Seguro Social
bd_274ea458c338d406 · schema v1 · pii pii-v1
Full breach record for Caja De Seguro Social →Threat-actor claim — not a regulatory filing
This row is a claim by the ransomware group Thegentlemen on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Source: Ransomware.live
Post text · scraped from the leak site
www.css.org.pa https://www.zoominfo.com/c/caja-de-seguro-social/455482072 www.css.gob.pa Caja de Seguro Social (CSS), the Panamanian Social Security Fund. The CSS is a public institution responsible for administering and governing the national social security and healthcare system in the Republic of Panama. Manages a network of hospitals and clinics nationwide, serving approximately 84% of Panama's population. 3TB of data, including pension, medical, and investment data. As gentlemen, we offered to pay a fair price for the mistake made, after which all data would be permanently deleted from our servers. The management decided that their influence on public opinion is so strong that the incident will remain unnoticed, so we are forced to publish proof of the hack and put the medical and pension databases containing 80% of Panama's population up for sale as a single package for 2 BTC.
Source provenance
- Source URL
- https://www.ransomware.live/id/Q2FqYSBEZSBTZWd1cm8gU29jaWFsQHRoZWdlbnRsZW1lbg==
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 14, 2026
- Raw hash
- 8f1a1e897d6ab7510d57896839456d14702e3ed40de6fa99e325dfc5b4e19804
Reporting entity
- Name
- thegentlemen
Victim entity
- Name
- Caja De Seguro Socialnorm: caja de seguro social
- Domain
- css.org.pa
- Industry
- Governmentllm
What this source establishes
- Source ceiling
- A leak-site claim can't tell us: discovery date · materiality · notification · affected count · confirmed data types · compliance clock. These stay blank until a regulatory filing or victim disclosure lands.
- Attack vector
- Ransomware· thegentlemen
- Threat actor
- ThegentlemenExternalFinancial
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.