CiberLATAMbywhalemate

EsSalud Lambayeque hit by S/1.4M fraud

EsSalud reported five unauthorized transfers totaling S/1,406,991 in Lambayeque and asked banks to freeze the recipient accounts.

Whalemate Labs · AI-assisted researchPublished:2 min read

EsSalud Lambayeque lost S/1,406,991 through five unauthorized bank transfers from a Red Prestacional account, in a case the institution described as alleged computer fraud. The complaint was sent to the National Police, the Public Ministry and the Technical Secretariat for Disciplinary Administrative Proceedings, while the executive presidency removed two officials from the network, including local administrator Erika López Cajas.

EsSalud Lambayeque lost S/1,406,991 through five unauthorized bank transfers from a Red Prestacional account, in a case the institution described as alleged computer fraud. The complaint was sent to the National Police, the Public Ministry and the Technical Secretariat for Disciplinary Administrative Proceedings, and the executive presidency later removed two officials from the network, including local administrator Erika López Cajas.

How was the fraud carried out?

The operation relied on a mix of phone fraud, remote access and bank credential use, according to Infobae Peru's coverage and the video material published by that outlet. That reconstruction cites usernames, passwords and a banking token used to complete the transfers.

Infobae Peru described the case as a phone and digital scam, not ransomware. In its video, the outlet also showed internal EsSalud Lambayeque records detailing the five unrecognized transfers and union statements confirming the use of remote-access tools such as AnyDesk and UltraViewer on the institutional computer from which passwords and the banking token were captured.

What did EsSalud do after detecting the theft?

EsSalud filed a criminal complaint and requested that the receiving accounts be frozen in an effort to recover the funds, according to television coverage and the Peruvian digital outlet that repeated the case. The institution also filed an urgent request with Scotiabank to block those accounts and trace the transactions.

EsSalud's institutional statement, cited by Diario Correo, described the loss of funds through five unauthorized bank transfers and framed the incident as alleged computer fraud involving unauthorized access and possible identity theft.

What administrative measures were taken?

EsSalud's executive presidency removed at least two officials from the Lambayeque Prestacional Network after the fraud, according to Diario Correo. Among them was local administrator Erika López Cajas.

That decision came on top of the referral of the case to criminal and administrative authorities. The file was handed over to the National Police, the Public Ministry and the Technical Secretariat for Disciplinary Administrative Proceedings of the network.

Is there confirmation of ransomware?

There is no strong official confirmation of ransomware against EsSalud Lambayeque in the verified material. What is confirmed is a digital theft involving unrecognized bank transfers, remote access and alleged computer fraud.

At the same time, a ransomware monitoring blog and a community platform reposted an entry about Centro Médico Especializado OSI: Healthcare Solutions as a victim of the kazu group, with the target domain centromedicoosi.com and a breach date of August 23, 2026. That record includes data that matches ransomware.live, but the available material does not provide enough independent verification of that incident or allow it to be linked to EsSalud Lambayeque.

Sources

View all