CiberLATAMbywhalemate

ARS Renacer and Hospifar listed by ransomware

DragonForce and Titan listed ARS Renacer and Grupo Hospifar on leak sites. Available reports cite sensitive data in the insurer case.

Whalemate Labs · AI-assisted researchPublished:2 min read

DragonForce published ARS Renacer, a Dominican Republic health risk administrator, on its ransomware leak site. Titan separately listed Grupo Hospifar S.R.L., an Argentine healthcare provider, on a similar extortion site.

DragonForce published ARS Renacer, a health risk administrator in the Dominican Republic, on its ransomware leak site. At the same time, Titan listed Grupo Hospifar S.R.L., an Argentine healthcare provider, on its own extortion site. In both cases, the material available points to ransomware activity records, not public confirmation from the affected organizations.

What is known about ARS Renacer?

ARS Renacer was added by DragonForce to a leak site, but GalaxyWarden described the case as an unverified claim because the company had not publicly confirmed an intrusion or data theft. The post also did not specify data categories or the number of people affected.

Dexpose attributed the incident to the exposure of sensitive medical and financial data and said it may have affected thousands of members. That same coverage says DragonForce posted the Dominican insurer as part of an alleged large-scale data theft. BreachSense, for its part, tied the case to a 340.54 GB leak and said it had indexed 24 accounts associated with the domain and 20 credentials from the domain itself, while noting that the record does not prove those items came from a confirmed breach at the insurer.

What happened with Grupo Hospifar?

Titan posted Grupo Hospifar S.R.L. on its leak site, and Ransomware.live recorded the company as a victim discovered on 2026-09-22, with the attack date also estimated as that same day. APJ One also included the company among Titan victims recorded on September 22, 2026, and classified it as a healthcare organization in Argentina.

Kalir described Titan's listing of Grupo Hospifar as an active and urgent incident for Argentine healthcare entities, but the available material does not include a statement from Hospifar, data volume, exposed categories, or public forensic evidence. In other words, there is a record of the leak site posting, but no independent confirmation of the scope or real impact on the firm.

How confirmed is the case?

The ARS Renacer case has two separate layers: a DragonForce post on a leak site and third-party reporting that attributes a possible exposure of sensitive data, with at least one source, GalaxyWarden, marking the episode as unverified. Grupo Hospifar also appears as a listing in Titan's leak ecosystem, but the available sources treat it as a record of activity, not as public proof of a confirmed intrusion.

Based on the available material, what can be verified is that both organizations appeared on ransomware listings, and that, in the sources cited, there is no official confirmation from the affected entities.

Sources

View all