On February 10, 2026, the Sanoviv Medical Institute appeared on the leak site operated by the ransomware group WorldLeaks. The Mexican holistic health facility, which treats patients from around the world for chronic conditions and preventive care, is claimed to have had internal files exfiltrated during a ransomware attack.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.
What Public Reporting Shows
Available reporting describes the incident as a classic ransomware operation in which attackers gained access, encrypted systems, and then exfiltrated data before demanding payment. The group published a listing for Sanoviv on its dark-web leak portal, signaling that negotiations had failed or that the victim had not met the ransom deadline. Public reporting indicates the exposed material consists of internal files, though the exact volume and specific categories of information remain unconfirmed in open sources. No precise count of affected individuals has been released; the breach therefore potentially touches every patient, staff member, vendor, or contractor whose records were stored in the compromised environment.
Sanoviv has not yet issued a public statement detailing the timeline of initial access, the date of encryption, or the precise data types involved. Industry research from sources such as DoxxScan™ continuous monitoring indicates that healthcare organizations frequently store names, dates of birth, medical histories, contact details, insurance information, and sometimes Social Security numbers or passport data for international patients. Any of these elements could be inside the stolen files.
Why This Matters for You and Your Family
When a medical provider is breached, the consequences reach far beyond the clinic. Medical histories, home addresses, and phone numbers are among the most sensitive records families possess. Once they leave a secure environment they can be sold, traded, or used to build profiles that make every member of the household easier to target. A parent who traveled to Rosarito for treatment may have listed children or a spouse as emergency contacts; those names and numbers are now at risk of appearing in future data sets. The breach therefore affects not only the person who received care but anyone whose details were entered into the same patient file or billing record.