Ransom! arsrenacer.com (SEP-2026)
A ransomware claim involving ARS Renacer, S.A. (arsrenacer.com), where threat actor dragonforce (AR) allegedly exfiltrated extensive health insurance data including PHI, affiliate identity records, financial details, and access credentials. The dump indicates high-impact exposure across the organization, creating significant risks for patient privacy, financial systems, and regulatory compliance in #DominicanRepublic (AR)

Incident Details

  • Victim: arsrenacer.com
  • Sector: Other
  • Country: AR
  • Actor: dragonforce
  • Source: http://xjhmtitnrdrgzw4vmsghirdoo2fk35a3tzj4enlmah4pvehdspydsiyd.onion/blog/?post_uuid=01cb9bb7-2f43-4e39-aef6-ef509ed5ecfd
  • Discovered: 2026-09-20T20:58:23.037069+00:00
  • Published: 2026-09-01T20:50:07.927335+00:00

Information

  • ARS Renacer, S.A. is a private Health Risk Administrator in the Dominican Republic, licensed by SISALRIL and a member of ADIMARS, serving hundreds of thousands of affiliates through 24 regional offices.
  • The leak is extensive, with 274,404 files exposed, including 158,693 critical and high-risk files.
  • Infrastructure and credential data were exposed, including user account folders, SSH access keys, command histories, Git configurations, and passwords or tokens for financial systems.
  • Affiliate databases were compromised, including names, national IDs, phone numbers, addresses, and backup files that may contain complete database dumps.
  • Employee payroll information was also included in the dump.
  • Medical and PHI data were exposed, including service authorizations, pre-certification records, medical records, prescriptions linked to diagnoses, and claims files.
  • Financial data was compromised, including transaction records, account files, reports, balance sheets, budgets, and secrets for financial systems.
  • The leak creates serious legal and regulatory exposure under Dominican data protection, clinical confidentiality, cybercrime, and SISALRIL protection requirements.
  • The incident could enable abuse of the Traspaso Digital system, blackmail of patients, business email compromise, synthetic identity theft, and mass legal claims.
  • The exposed data is highly sensitive and difficult to mitigate because identities and medical histories are permanent and cannot simply be invalidated.

Disclaimer: This post is based on public claims made by the ransomware group "dragonforce". I cannot confirm the accuracy of the information. However, I would be happy to share any official statement from the affected organization to provide clarification.

monitored by: ransomware.live