CiberLATAMbywhalemate

Chile’s Hospital Clínico cited in Direwolf leak

Darkfield, RecentBreaches and Hackmanac added more records on the Hospital Clínico Universidad de Chile case, still unconfirmed.

Whalemate Labs · AI-assisted researchPublished:Updated 4 min read

Darkfield and RecentBreaches added new entries on Hospital Clínico Universidad de Chile in the context of Direwolf, while Hackmanac issued an alert marked pending verification and MedRisk.io said the victims had not been confirmed.

Update September 3, 2026: Darkfield and RecentBreaches added entries for Hospital Clínico Universidad de Chile as a case listed by Direwolf, while Hackmanac issued an alert marked "Pending verification" and MedRisk.io said the victims had not been confirmed as of the close. The original report also remains without public validation from the hospital or Chilean authorities.

Ransomware.live listed Hospital Clínico Universidad de Chile as an alleged Direwolf victim and estimated 240 GB of data had been exfiltrated, with an estimated attack date of 2026-08-30, target domain redclinica.cl, country Chile, and health care as the sector. HookPhish repeated the claim and framed it as a ransomware incident, along with several monitoring feeds. No independent confirmation from the hospital or Chilean authorities appears in the available results.

What do the trackers say about the case?

Both sources describe the same claim, Direwolf allegedly hit Hospital Clínico Universidad de Chile and posted the case on a leak site, according to the available material. Ransomware.live lists the institution as a victim and cites 240 GB of exfiltrated data, 1,633 affected users, and an external attack surface of 80 assets, while HookPhish repeats the attribution and the data volume. Neither entry includes official verification.

Security Arsenal added context by saying that, within a 24 hour window on August 30, 2026, Direwolf allegedly added three new victims to its leak site, including Hospital Clínico Universidad de Chile, Erdem Hospital, and THQ Nordic. FalconFeeds.io and CronUp replicated that same post in their feeds, and Ransom-DB also circulated the hospital name. Those reports show the case spreading across multiple monitors, but they do not provide independent technical evidence.

Darkfield logged Hospital Clínico Universidad de Chile as "Listed for ransom" and categorized it as a university teaching hospital in Chile, without confirming operational impact or leaked data. RecentBreaches, meanwhile, described the case as "unconfirmed breach claims" and maintained a specific risk entry, DoxxScan, making it explicit that there is no independent verification of intrusion or exfiltration. In another entry on the same platform, Direwolf remains the only group associated with the hospital.

What is the scope of the allegation?

The material reviewed does not allow confirmation of the real impact on the institution or what type of information may have been exposed. Galaxy Warden added that there is no clear incident date, no verified victim count, and no confirmed data categories, and stressed that the episode should be treated as an unverified claim based only on Direwolf's leak site. HookPhish's reference also lists CL as the region and redclinica.cl as the target domain.

HookPhish presented the case as a ransomware attack against the hospital and included technical fields such as domain, health care sector, country CL, and breach and discovery dates, although it did not cite an official statement from the hospital or from CERT or Chilean authorities. Ransom-DB, on X, also posted that Direwolf had "published" Hospital Clínico Universidad de Chile, with location in Independencia, Santiago, and a public teaching hospital sector, but without mentioning confirmations or denials.

Hackmanac issued an alert on the same case with a "Pending verification" status. In that post, it attributed a supposed 240 GB theft to Direwolf and detailed the categories allegedly exposed, including medical records, PHI, clinical histories from 2023 to 2026, biopsies, documents, GES admissions, and master files, all within a classification that remains unverified publicly.

MedRisk.io covered the same Direwolf batch of victims and said Hospital Clínico Universidad de Chile appeared almost at the same time as Erdem Hospital. According to that report, both RansomLook and ransomware.live show identical timestamps for the two entries on August 30, 2026, and as of publication there was no confirmation for any of the victims.

What is still needed to confirm the case?

A statement from Hospital Clínico Universidad de Chile or a communication from Chilean authorities is still needed to corroborate the intrusion and any possible data theft. Based on the information available, the episode remains an allegation published by ransomware trackers, not an officially validated fact.

A personal incident-analysis blog titled "Ransom! Hospital Clínico Universidad de Chile (AUG-2026)" repeated that the hospital would have been targeted by direwolf, with operational disruption and encrypted data, but the piece relies on third-party reports and does not provide direct evidence or cite statements from the institution. Galaxy Warden also mentioned the hospital among the Direwolf listings in that same batch of posts, while keeping the wording as "listed" rather than claiming a confirmed compromise.

Sources

View all