Skip to content
Back to Blog
high severity September 03, 2026 · 4 min read Unverified claim — what this is

ligacancerguate.org Listed by Krybit Ransomware Group

If you are a customer of ligacancerguate.org, here’s what is being claimed, and what it would mean for you.

INCAN — Instituto de Cancerología y Hospital Dr. Bernardo del Valle S. is Guatemala's premier private cancer treatmen...

— from Krybit’s own leak-site posting. This is the group’s claim, quoted verbatim; it is not GalaxyWarden’s reporting and has not been independently verified.
ligacancerguate.org Listed by Krybit Ransomware Group

The Krybit ransomware-extortion group has listed ligacancerguate.org on its leak site. According to the listing, the group claims to have obtained data belonging to patients of INCAN — Instituto de Cancerología y Hospital Dr. Bernardo del Valle S., Guatemala’s premier private cancer treatment centre. The filing date is September 03, 2026. The organisation has not publicly confirmed the claim as of writing.

Watch ligacancerguate.org

Get alerted the next time ligacancerguate.org files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.

We’ll email you only about ligacancerguate.org’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.

Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.

This means that if the claim is accurate, records that once existed only inside the hospital’s systems may now sit on a criminal server. For anyone treated or billed at INCAN, the immediate question is whether their own information is among the files the group says it holds. The record does not state how many people were affected, nor does it name any specific categories of information. It simply lists the organisation and posts a sample that the group says proves access.

What a ransomware leak-site listing actually establishes

A listing on a ransomware group’s leak site is a public accusation, not proof. These crews frequently publish names of targets to create pressure, sometimes before any data has been taken, sometimes using material recycled from earlier incidents, and sometimes inflating what they actually possess. The sample they post can be genuine but limited, or it can be fabricated. Until the organisation itself, a regulator, or an independent forensic report confirms that an intrusion occurred and data left the premises, the claim remains unverified.

Exposure Pack · one payment
The full list, and what to lock in ten minutes.
  • Every indexed leak tied to your address — all of them, named and dated
  • What this kind of incident typically exposes
  • A ten-minute lock list written for this kind of organisation
One payment. Nothing renews, and no account is created. Emailed to you within a minute.

Real confirmation usually arrives in the form of direct notifications to affected individuals or mandatory regulatory filings that describe the breach with specific dates and categories. A leak-site post by itself supplies none of those. It is marketing material designed to extract payment. Many organisations ultimately pay quietly and the listing disappears; others prove the claim was exaggerated or false. The presence of ligacancerguate.org on Krybit’s page therefore tells you that the group wants the hospital to believe its data is at risk. It does not yet tell you that the risk has materialised for any particular patient.

The pattern seen across healthcare providers in Latin America

Ransomware operators have repeatedly targeted hospitals and cancer clinics in the region, using the sensitivity of patient records as leverage. The tactic is consistent: list the facility publicly, threaten to publish or sell the data, and wait for contact. In many documented cases the final outcome has ranged from full extortion payment to negotiated removal of the listing without any independent evidence that large volumes of data were allegedly exfiltrated. For patients this pattern means the same uncertainty appears again and again — an alarming claim, silence from the provider, and no immediate way to know whether their specific record is involved.

What remains under your control is how you respond to the possibility. Because no permanent government or biographic identifiers are known to have been listed in this filing, the long-term identity risks that accompany many other breaches are not automatically present here. The record does not indicate that Social Security numbers, passports, or equivalent national IDs were taken.

Your password, if one was associated with an INCAN patient portal

The listing mentions credential exposure but does not disclose how passwords were stored. When the storage scheme is unknown, treat the credential as potentially usable elsewhere. If you have an account on ligacancerguate.org or any linked patient portal, change that password immediately from a different device and do not reuse it anywhere. This single step closes the most direct route an attacker could take if the claimed credential material is genuine.

Because the hospital is a cancer-treatment centre, any patient portal access could also have contained appointment details, treatment summaries or billing records. Even without national identifiers, that information can be used for impersonation or targeted fraud. Review recent statements and explanations of benefits for unfamiliar charges. Contact INCAN directly if you have not received any communication from them about this listing; absence of a letter usually indicates you were not in the group they consider affected, but anyone who has changed address since the claimed events should verify their status with the hospital.

What you should do today

  • Change your ligacancerguate.org password from a device that has never been used to log into the portal before, then enable two-factor authentication if the option exists.
  • Monitor accounts linked to your email address used at INCAN; watch for password-reset attempts or unfamiliar login notifications.
  • Review medical and billing statements from INCAN for any activity you do not recognise and dispute it promptly.
  • Contact the hospital’s patient services to ask whether they have confirmed an incident and whether your record was involved.
  • Place a fraud alert with your bank or credit providers if you ever shared banking details during treatment or billing.

GalaxyWarden provides continuous monitoring across 13.1B+ breach records and 100+ platforms, with identity-chain mapping and remediation handled by specialists.

What the free scan actually returns

Sample resultyou@email.comIllustrative — not a real person

Found on people-search siteswe remove these

These listings are live, public, and legal to remove — and removing them is what we do.

value redacted in this sampleage, relatives, address historySpokeo
value redacted in this samplephone, household, property recordsBeenVerified
value redacted in this sample580 companies checked

Found in breach recordsverifiedreported — unverified

Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.

verifiedvalue redacted in this samplepassword + phone · 2024telecom breach
unverifiedvalue redacted in this sampleclaimed in ransomware listing · 2026leak-site claim

Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.

Check your exposure
ligacancerguate.org is one listing. Your email is probably in others.
We can’t confirm any single incident against the sources we search, so we won’t pretend to. What we can show you is your own exposure — your email against 13.1B+ leaked records and the sites that publish your address. About 15 seconds. No account, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Report details & sourcing

Severity High the filing does not enumerate what was exposed
Disclosed September 03, 2026
Last reviewed September 3, 2026
Affected Unconfirmed
Unverified claim — what this report is
This page documents a public listing on a ransomware/extortion group’s leak site, tracked via public threat-intelligence sources. A listing is the attacker’s claim. GalaxyWarden aggregates and reports such claims; we have not independently verified that a breach occurred, what data (if any) was taken, or the accuracy of anything the group asserts, and the named organisation has not necessarily confirmed the incident. Sections above describe what the listing shows and the group’s documented history — not verified findings about the named organisation. If you represent this organisation and believe anything here is inaccurate, tell us and we’ll review it promptly.
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email