Chile reports ransomware attacks on health sector
August ended with at least 10 organizations hit by ransomware in Chile, including cases at the University of Chile Clinical Hospital.
August saw at least 10 organizations in Chile affected by ransomware, including the University of Chile Clinical Hospital and the Ferrero Institute of Neurology and Sleep. In both cases, public reporting relies on leak site listings and third-party monitoring, without official confirmation from the victims.
August saw at least 10 organizations in Chile affected by ransomware, including the University of Chile Clinical Hospital. Monitoring from different teams also added the Ferrero Institute of Neurology and Sleep, although in both incidents the public information still depends on leak site listings and third-party attribution.
What happened with the University of Chile Clinical Hospital?
The hospital was linked by CronUp to an incident attributed to the Direwolf group, with an alleged data publication that could total 240 GB of exfiltrated information, according to El Morrocotudo. That same reference was flagged by a threat intel account on X under the VenariX en Español brand, which reported that Direwolf had listed the hospital as a possible ransomware victim.
A LinkedIn commentary by José Fernández Figueroa also says that on August 30 the Direwolf group posted on its leak site that it had attacked the University of Chile Clinical Hospital. That text, however, presents the claim as part of a comment on the role of the state, not as official confirmation from the hospital.
What is known about the Ferrero Institute case?
The Ferrero Institute of Neurology and Sleep was listed by the Kazu group on its leak site around September 7, 2026, with a claim framing it as a ransomware extortion campaign. According to the site attributed to Kazu, the material would include 636 GB, 474,826 files, and 103,315 users.
GalaxyWarden detailed those alleged volumes and noted that the publication only documents the public listing on an extortion group leak site. The report adds that, as of publication, the Ferrero Institute had not issued a public confirmation of the attack or a data breach.
RecentBreaches agreed that the institute was listed by Kazu, but was explicit that the claim has not been verified. BreachSense, meanwhile, registered the center as a victim claimed by Kazu with a leak size of 636 GB, while clarifying that it only indexes attributions based on external sources and provides no independent evidence of exfiltration or actual publication.
What do these reports show about the region?
The Chile cases and the listing of the Ferrero Institute in Argentina show a pattern in which public visibility into several health-sector incidents still depends on leak sites and monitoring platforms. In the Chilean case, at least two threat intel sources, CronUp and VenariX en Español, agree on the Direwolf incident involving the University of Chile Clinical Hospital.
That leaves both cases on similar footing, with claims posted by ransomware actors and tracking by third parties, but no public confirmation from the affected institutions in the materials reviewed.
Sources
- VenariX en Español (@_venarixES_)x.com· VenariX en Español (X)
- kazunexus8.8bitsecurity.com· Nexus8 (8bitsecurity)
- Instituto Ferrero de Neurología y Sueñobreachsense.com· BreachSense
- El Estado que financia y el Estado que exigees.linkedin.com· LinkedIn
- Ransomware marca récord en Chile: agosto tuvo la mayor cantidad de ataques registradoselmorrocotudo.cl· El Morrocotudo
- Instituto Ferrero de Neurología y Sueño Listed by Kazu ...galaxywarden.com· GalaxyWarden
- Instituto Ferrero de Neurología y Sueño Ransomware Claim (2026) — What’s Alleged & Am I Affected?recentbreaches.com· RecentBreaches



