ligacancerguate.org Listed by Krybit Ransomware Group
If you are a customer of ligacancerguate.org, here’s what is being claimed, and what it would mean for you.
INCAN — Instituto de Cancerología y Hospital Dr. Bernardo del Valle S. is Guatemala's premier private cancer treatmen...
— from Krybit’s own leak-site posting. This is the group’s claim, quoted verbatim; it is not GalaxyWarden’s reporting and has not been independently verified.
The Krybit ransomware-extortion group has listed ligacancerguate.org on its leak site. According to the listing, the group claims to have obtained data belonging to patients of INCAN — Instituto de Cancerología y Hospital Dr. Bernardo del Valle S., Guatemala’s premier private cancer treatment centre. The filing date is September 03, 2026. The organisation has not publicly confirmed the claim as of writing.
Watch ligacancerguate.org
Get alerted the next time ligacancerguate.org files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about ligacancerguate.org’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
This means that if the claim is accurate, records that once existed only inside the hospital’s systems may now sit on a criminal server. For anyone treated or billed at INCAN, the immediate question is whether their own information is among the files the group says it holds. The record does not state how many people were affected, nor does it name any specific categories of information. It simply lists the organisation and posts a sample that the group says proves access.
What a ransomware leak-site listing actually establishes
A listing on a ransomware group’s leak site is a public accusation, not proof. These crews frequently publish names of targets to create pressure, sometimes before any data has been taken, sometimes using material recycled from earlier incidents, and sometimes inflating what they actually possess. The sample they post can be genuine but limited, or it can be fabricated. Until the organisation itself, a regulator, or an independent forensic report confirms that an intrusion occurred and data left the premises, the claim remains unverified.
- Every indexed leak tied to your address — all of them, named and dated
- What this kind of incident typically exposes
- A ten-minute lock list written for this kind of organisation
Real confirmation usually arrives in the form of direct notifications to affected individuals or mandatory regulatory filings that describe the breach with specific dates and categories. A leak-site post by itself supplies none of those. It is marketing material designed to extract payment. Many organisations ultimately pay quietly and the listing disappears; others prove the claim was exaggerated or false. The presence of ligacancerguate.org on Krybit’s page therefore tells you that the group wants the hospital to believe its data is at risk. It does not yet tell you that the risk has materialised for any particular patient.
The pattern seen across healthcare providers in Latin America
Ransomware operators have repeatedly targeted hospitals and cancer clinics in the region, using the sensitivity of patient records as leverage. The tactic is consistent: list the facility publicly, threaten to publish or sell the data, and wait for contact. In many documented cases the final outcome has ranged from full extortion payment to negotiated removal of the listing without any independent evidence that large volumes of data were allegedly exfiltrated. For patients this pattern means the same uncertainty appears again and again — an alarming claim, silence from the provider, and no immediate way to know whether their specific record is involved.
What remains under your control is how you respond to the possibility. Because no permanent government or biographic identifiers are known to have been listed in this filing, the long-term identity risks that accompany many other breaches are not automatically present here. The record does not indicate that Social Security numbers, passports, or equivalent national IDs were taken.
Your password, if one was associated with an INCAN patient portal
The listing mentions credential exposure but does not disclose how passwords were stored. When the storage scheme is unknown, treat the credential as potentially usable elsewhere. If you have an account on ligacancerguate.org or any linked patient portal, change that password immediately from a different device and do not reuse it anywhere. This single step closes the most direct route an attacker could take if the claimed credential material is genuine.
Because the hospital is a cancer-treatment centre, any patient portal access could also have contained appointment details, treatment summaries or billing records. Even without national identifiers, that information can be used for impersonation or targeted fraud. Review recent statements and explanations of benefits for unfamiliar charges. Contact INCAN directly if you have not received any communication from them about this listing; absence of a letter usually indicates you were not in the group they consider affected, but anyone who has changed address since the claimed events should verify their status with the hospital.
What you should do today
- Change your ligacancerguate.org password from a device that has never been used to log into the portal before, then enable two-factor authentication if the option exists.
- Monitor accounts linked to your email address used at INCAN; watch for password-reset attempts or unfamiliar login notifications.
- Review medical and billing statements from INCAN for any activity you do not recognise and dispute it promptly.
- Contact the hospital’s patient services to ask whether they have confirmed an incident and whether your record was involved.
- Place a fraud alert with your bank or credit providers if you ever shared banking details during treatment or billing.
GalaxyWarden provides continuous monitoring across 13.1B+ breach records and 100+ platforms, with identity-chain mapping and remediation handled by specialists.
What the free scan actually returns
Found on people-search siteswe remove these
These listings are live, public, and legal to remove — and removing them is what we do.
Found in breach recordsverifiedreported — unverified
Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.
Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.
Report details & sourcing
Related breaches
diakonie-apolda.de Listed by Krybit Ransomware Group
Diakoniewerk Apolda gGmbH is a German non-profit social welfare organization (gemeinnützige GmbH) fo…
harputyapi.com Listed by Krybit Ransomware Group
Harput Yapı is an Istanbul-based residential real estate developer and construction company operatin…
appliancefactory.com Listed by INC Ransom Ransomware Group
Appliance Factory & Mattress Kingdom offers a wide range of discount appliances and mattresses, prov…