The double extortion of a Russian ransomware threatens the medical records that Diater has kept for 10 years.
Spanish biopharmaceutical firm Diater has appeared on the dark web victim list published by the ransomware group DeadLock, which is using a double extortion strategy — encrypting data and threatening to publish it. The breach reportedly affects up to a decade of sensitive medical records belonging to patients and healthcare professionals.
Why this matters: Medical records are not recoverable the way a password is. If DeadLock publishes what it took from Diater, patients cannot change their diagnoses, test results, or treatment histories. Ten years of data means the exposure is deep. Double extortion makes it worse: the company is under pressure to pay, and the people whose data is at stake have no say in that negotiation and no way to protect themselves. This is the core problem with how healthcare organizations hold sensitive data — the patients bear the risk, but the company makes the call.
Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance
This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.