DisclosureLens
GLOBALtranslated → enUnknownRansomwareRansomhouseLow

HOSPITAL CLINIC DE BARCELONA

bd_d064656e1bd26af4 · schema v1 · pii pii-v1

Severity

Low

Discovered

Filed

May 17, 2026

To disclose

Affected

Not disclosed

Linked

2 filings

Confidence

60%
Full breach record for HOSPITAL CLINIC DE BARCELONA2 incidents on file

Press / market disclosure — not a breach-notification filing

A media or market posting that confirms an incident but carries no breach-notification fields, so compliance clocks aren't assessable. The summary below is extracted from the coverage and machine-translated to English — verify against the source.

Summary

machine-translated

Hackers demand $4.5 million from a hospital in Spain. Hospital Clínic de Barcelona: A Spanish hospital (Hospital Clínic de Barcelona) was the victim of a cyberattack carried out by the criminal group RansomHouse, which demanded $4.5 million not to disclose patient data. The regional government of Catalonia warned that it would not pay, resulting in a "high risk" of data leak. Cybercriminals practice double extortion. Although the hospital has not lost any data according to Catalonia's Cybersecurity Agency, the attackers had access to four terabytes of information. The police will set up a "cyberpatrol" to prevent leaks and arrest those responsible. Linked ransomware group: ransomhouse.

Incident timeline — mostly unverified

? — ?

Breach window unknown

May 17, 2026

Press report

Corroborated · see linked filings

Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.

Attack → press

Compliance clock

Not assessable

This filing is one of 2 about the same incident.View merged incident

Linked disclosures

Why this link?

Ransomware claims (1)

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market reportThis record

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filing

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.

Source ceiling

  • incident type + narrative only (may be machine-translated)
  • discovery date
  • materiality
  • affected count
  • data types
  • compliance clock

The ✕ fields stay blank until a regulatory filing or victim disclosure lands.

About this groupFirst seen 2021-06-01

ransomhouse

According to ransomware.live, RansomHouse is a double-extortion RaaS operation active since late 2021, attributed to the threat actor "Jolly Scorpius," targeting over 120 organizations across healthcare, finance, transportation, and government, recently upgrading to a multi-layered dual-key encryption architecture.

213 tracked hereFull profile →