A ransomware crew calling itself Aurora says it has taken the medication records of employees at Laboratorios Roemmers, the Argentine pharmaceutical company, down to which staff were given clonazepam, alprazolam or diazepam at the company's own nursing station. The claim, posted on 1 October and recorded by the independent tracker ransomware.live on its victim page for the listing, also advertises 82 GB of drug formulations.
Roemmers was one of three health organisations in three South American countries to appear on leak sites in the week beginning 28 September. 3AM listed the Colombian health insurer Coosalud EPS, and RansomHouse named a public psychiatric hospital in Lima. None of the three has confirmed an incident that we could find at the time of writing.
Psychiatric prescriptions, ID numbers and drug recipes
Aurora's post, which describes Roemmers as Argentina's largest drugmaker by revenue, sets out its alleged haul in more detail than most. It claims the national identity numbers (CUIL) of 4,207 employees, combined with dates of birth and health insurance affiliations; employee-by-employee records of psychiatric medication dispensed on site; COVID-19 symptom logs, doctors' notes and return-to-work clearances; and pre-employment medical exam results.
The commercial material is just as pointed: the 82 GB of formulations, which the gang says cover every product the company makes, and 14 GB of internal pricing strategy and competitive intelligence. Infostealer figures from Hudson Rock shown on the tracker page count 53 compromised users linked to the company's domain and no compromised employees. That is background exposure, not proof of how any intrusion began.
Aurora is a young operation. Its first listing in our incident tracking is dated 29 April 2026, and it has 41 claims since, only two of them in South America. It is profiled on our actor page.
An insurer and a hospital that serves the poor
3AM added coosalud.com on 28 September. Its post describes Coosalud as one of Colombia's major EPS bodies, the entities that manage members' cover under the national health system, but names no specific data. The Hudson Rock figures for Coosalud's domain are far larger than for Roemmers: 30 compromised employees and 4,342 compromised users.
RansomHouse listed Hospital Hermilio Valdizán on 1 October. The listing's own profile calls it a public psychiatric hospital run by Peru's Ministry of Health whose patients are mostly low-income, many of them covered by the state SIS insurance scheme. The tracker gives an estimated attack date of 21 August, six weeks before the post went up.
An ordinary count, an unusual mix
The volume itself is not the story. Our tracking holds 13 claims against South American organisations for the week so far, inside the range of 8 to 22 a week seen since July, and three healthcare listings is no more than the four seen in two August weeks. What stands out is the profile: a national drugmaker, a major insurer and a public psychiatric hospital. Every listing here was written by the gangs themselves, crews do exaggerate and recycle old data, and the leak sites sit on .onion addresses, which we do not link. We saw a similar mix in September, when a court and a hospital landed on the region's leak sites.
Roemmers staff should treat their CUIL as exposed
Employees in a dump like this cannot change their ID numbers or medical history. They should expect phishing that quotes real personal details and watch for credit or benefit applications opened in their name. Organisations in Argentina that confirm a personal data breach answer to the national data protection authority, the AAIP. Country context sits on our Argentina, Colombia and Peru pages.
A stolen price list ages in months. A record of who in a workforce takes anti-anxiety medication does not, and that is what Aurora chose to lead with.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.