CiberLATAMbywhalemate

Hospital Santa Marta extortion conviction upheld

Federal District judges upheld the conviction of two hackers who accessed Santa Marta Hospital data and demanded 43 bitcoins.

Whalemate Labs · AI-assisted researchPublished:3 min read

The Federal District court upheld the conviction of two defendants in the Santa Marta Hospital case for device intrusion, extortion and attacking the security of a public utility service. According to the complaint, they accessed a secondary hospital database without authorization, took patient documents and information, and then demanded 43 bitcoins under threat of disclosure.

The Federal District court upheld the conviction of two defendants in the Santa Marta Hospital case for device intrusion, extortion and attacking the security of a public utility service. According to the complaint, they accessed a secondary hospital database without authorization, took patient documents and information, and then demanded 43 bitcoins under threat of disclosure.

What did the court decide?

The TJDFT unanimously upheld the conviction of two hackers over a cyberattack against Santa Marta Hospital. The ruling kept the penalties for device intrusion, extortion and attacking the security of a public utility service, according to Convergência Digital and Valor.

The case was tied to the bitcoin ransom demand after patient documents and information were obtained. Correio Braziliense also reported that the amount demanded, 43 bitcoins, was estimated by the outlet at about R$16,807,027.66 based on the exchange rate it used in its report.

What did the investigation cited in the case say?

According to Correio Braziliense, the investigative report cited in the case described the defendants as planning a ransomware attack to disrupt the hospital's systems. The same coverage added that the group sought to halt the facility's operations and that the malware had destructive potential.

That wording, however, refers to the intent attributed to the defendants and does not show that ransomware was installed or executed. The available material only confirms the intrusion, the data theft and the later payment demand.

What other data does the health-sector picture in Brazil show?

ANPD recorded 43 formal security incident reports in Brazil's health sector between January and early September 2026. The report cited by Comprova breaks that down into 10 credential theft cases, eight unauthorized access incidents, seven improper disclosures of personal data and five data kidnappings.

GauchaZH also said that 88% of those formal reports came from the private sector. The figure reinforces that the reported incidents are not concentrated in just one type of organization within the health system.

Was there another recent incident in the region?

Yes. INCAN reported a cybersecurity incident that temporarily affected its Radiation Therapy Department. The institution said services were fully restored on September 11 and, according to La Hora, the case was reported to the Public Prosecutor's Office.

This material does not publicly confirm that episode was ransomware. What is established is the temporary impact on radiation therapy and the later full restoration of the service.

Sources

View all