Incransom, the extortion gang that has posted multiple healthcare organizations this year, has added an Italian private healthcare network to its leak site. Trackers logged Policlinico Triestino on September 2, and the tracker record for the listing carries no stolen-file samples, volume figures, or deadline so far.
Policlinico Triestino S.p.A. operates hospitals, nursing homes, and outpatient clinics across the Trieste area of northeastern Italy. The listing names the company but attaches no claim details, a pattern trackers see often in the hours after a post goes up.
The claim is unverified, and the company has not issued a public statement. Incransom previously posted US healthcare organizations this summer, including a North Carolina eye care group whose patient records were among the files released.
European hospital networks have become a regular target for extortion crews, with operators increasingly treating ransomware as a data-theft play rather than a pure encryption attack. For Policlinico Triestino’s patients, the practical advice is to hold off on any action until the organization confirms scope, and to stay alert for phishing messages that cite the incident. Health data carries special protections under GDPR, so a confirmed exposure would trigger notification duties toward Italy’s data protection authority and affected patients. Healthcare CISOs elsewhere should treat the claim as a reminder that bare leak-site postings often precede confirmed disclosures by days or weeks.