Lockbit5 and Space Bears stack small European clinics on leak sites

Lockbit5 and Space Bears posted a Dutch primary care center and an Italian eye clinic in the same stretch, with neither claim showing proof.

MedRisk Staff
By
2 Min Read

Two ransomware operations stacked small European care providers onto their leak sites in the same early-September stretch, posting bare listings that name no stolen data categories, volumes, or victim counts. Lockbit5 listed Huisartsencentrum Klein Iterson, a Dutch primary care center, on September 4 as part of a same-minute burst of three victims. Space Bears separately posted Studio Oculistico Ciraci, an ophthalmology clinic in Bari, Italy, that opened in 1989 and is accredited with the Italian National Health Service.

Neither provider has confirmed an intrusion, and trackers caution that claims published without file samples are often recycled or inflated. The Italian clinic focuses on glaucoma and vitreoretinal disease, so any real exposure would touch decades of diagnostic imaging and treatment records for patients protected by Europe’s strict data rules. A confirmed compromise at the Dutch center would trigger notification duties toward the national health authority and affected patients under GDPR.

Small European practices remain attractive to extortion crews because many run older practice-management software, share networks with attached pharmacies or labs, and lack dedicated security staff. Bare listings typically precede confirmed disclosures by days or weeks, if they precede them at all.

For CISOs across the region, the pair of posts is a reminder to verify vendor and partner connections into primary care networks and specialty clinics. Patients should wait for official communication from their provider before acting on third-party claims.

Share This Article