lenmed.co.za listed by the lockbit3 ransomware group
lenmed.co.za
Overview
On 7 May 2024, the LockBit 3.0 ransomware group listed the South African hospital group Lenmed on its data leak site. The listing identified the Maputo Private Hospital in Mozambique, part of the Lenmed network, as the affected facility. The group claimed to have encrypted systems and exfiltrated data, a standard double-extortion pattern observed across its operations.
What was published
The ransomware group did not disclose the volume or precise categories of data taken from the hospital. Its listing stated that data was exfiltrated and encrypted, which in similar LockBit 3.0 incidents has included patient records, administrative documents and internal correspondence. No sample files were made available on the leak site at the time of analysis.
Risks for affected individuals
Maputo Private Hospital serves patients in Mozambique and operates in both English and Portuguese. If patient data was among the exfiltrated files, affected individuals could face identity fraud, phishing built on medical history, and misuse of personal identifiers. Staff records and financial documents, if present, carry similar exposure.
What remains unknown
The total number of records, the exact categories of data, and whether any information was published before the group removed the listing remain unconfirmed. Lenmed has not issued a public statement about the incident, and no independent verification of the claimed data volume exists.
What affected people should do
Patients and staff of Maputo Private Hospital should watch for unsolicited messages that reference personal details, change passwords for accounts linked to the hospital, and contact the facility directly for official guidance. Organisations should treat any communication claiming to hold hospital data as untrusted.
Sources
- http://lockbit3olp7oetlc4tl5zydnoluphh7fvdt5oa6arcp2757r7xkutid.onion/post/npcm2gCiKtmXnNYB6639e76ff4108