Ransomware group Direwolf has listed Quironsalud, Spain’s largest private hospital operator, on its leak site, according to ransomware.live.
The listing appeared August 10 with an estimated attack date of the same day. Quironsalud runs a portfolio of roughly 80 hospitals and medical centers across Spain and is part of the Fresenius Helios group, which positions it as one of Europe’s largest hospital networks. No volume of stolen data was specified in the listing.
Tracker telemetry adds context on exposure: infostealer logs tied to the quironsalud.com domain show 25 compromised employee credentials and more than 4,500 compromised user accounts, a common precursor to ransomware intrusions. The same day, Direwolf also posted AliveCor, the US ECG device maker, and Health Carousel, a healthcare staffing firm with US and Philippine operations.
Quironsalud has not publicly confirmed the claim. Hospitals facing similar credential exposure should treat leaked login data as an active intrusion signal, reset affected accounts, and review remote access and identity provider logs before an extortion demand arrives. For large international care networks, the incident also highlights how third-party credential leakage at the domain level can precede an attack on clinical infrastructure.
