HOSPITAL CLINIC DE BARCELONA
bd_d064656e1bd26af4 · schema v1 · pii pii-v1
Full breach record for HOSPITAL CLINIC DE BARCELONA →2 incidents on filePress / market disclosure — not a breach-notification filing
A media or market posting that confirms an incident but carries no breach-notification fields, so compliance clocks aren't assessable. The summary below is extracted from the coverage and machine-translated to English — verify against the source.
Summary
machine-translatedHackers demand $4.5 million from a hospital in Spain. Hospital Clínic de Barcelona: A Spanish hospital (Hospital Clínic de Barcelona) was the victim of a cyberattack carried out by the criminal group RansomHouse, which demanded $4.5 million not to disclose patient data. The regional government of Catalonia warned that it would not pay, resulting in a "high risk" of data leak. Cybercriminals practice double extortion. Although the hospital has not lost any data according to Catalonia's Cybersecurity Agency, the attackers had access to four terabytes of information. The police will set up a "cyberpatrol" to prevent leaks and arrest those responsible. Linked ransomware group: ransomhouse.
J jump to incidentP pin to compareR raw source
Incident timeline — mostly unverified
? — ?
Breach window unknown
May 17, 2026
Press report
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Attack → press
—
Compliance clock
Not assessable
Linked disclosures
Why this link?Ransomware claims (1)
- Leak Siteransomhousebd_34727a2172c7cfca2026-05-17Candidate
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
Source ceiling
- incident type + narrative only (may be machine-translated)
- discovery date
- materiality
- affected count
- data types
- compliance clock
The ✕ fields stay blank until a regulatory filing or victim disclosure lands.
ransomhouse
According to ransomware.live, RansomHouse is a double-extortion RaaS operation active since late 2021, attributed to the threat actor "Jolly Scorpius," targeting over 120 organizations across healthcare, finance, transportation, and government, recently upgrading to a multi-layered dual-key encryption architecture.