All ransomware incidents
Ransomware group thegentlemen hits Hospital de la Santa Creu i Sant Pau
Hospital de la Santa Creu i Sant Pau — a healthcare target operating in ES has been listed by the thegentlemen ransomware group on 2026-10-02. The information below reflects what the threat actor has publicly claimed on their leak site; the details have not been independently verified.
Incident Report
| Target Organization | Hospital de la Santa Creu i Sant Pau |
|---|---|
| Threat Group | thegentlemen |
| Summary | santpau.cat zoominfo.com/c/hospital-de-la-santa-creu-i-sant-pau/372615247 Hospital de la Santa Creu i Sant Pau is a 625-year-old Barcelona medical institution (founded 1401) and a UNESCO World Heritage Site since 1997. It combines a major academic hospital (2009) with the Recinte Modernista, a masterpiece of Catalan Modernism designed by Lluís Domènech i Montaner. The hospital employs ~4,965 people, runs on a ~€490M annual budget, and has 600 beds and 25 operating rooms, serving 400,000+ patients a year. Its research institute (IR Sant Pau, founded 1992) employs 1,632 staff with 1,058+ publications and 705 active clinical trials. |
| Date of Breach | 2026-10-02 |
| Discovery Date | 2026-10-03 |
| Region | ES |
| Target Domain | santpau.cat |
| Business Sector | Healthcare |
| Severity | MEDIUM |
Claim by thegentlemen
santpau.cat zoominfo.com/c/hospital-de-la-santa-creu-i-sant-pau/372615247 Hospital de la Santa Creu i Sant Pau is a 625-year-old Barcelona medical institution (founded 1401) and a UNESCO World Heritage Site since 1997. It combines a major academic hospital (2009) with the Recinte Modernista, a masterpiece of Catalan Modernism designed by Lluís Domènech i Montaner. The hospital employs ~4,965 people, runs on a ~€490M annual budget, and has 600 beds and 25 operating rooms, serving 400,000+ patients a year. Its research institute (IR Sant Pau, founded 1992) employs 1,632 staff with 1,058+ publications and 705 active clinical trials.
Posted by the thegentlemen threat actor on its public leak site. This is the group's own statement and has not been independently verified by HackerFeeds.
Sources
Disclaimer
HackerFeeds does not engage in the exfiltration, downloading, taking, hosting, viewing, reposting, or disclosure of any stolen information. All breach data reported here is sourced from publicly available threat intelligence feeds for awareness purposes only.

