Cyber & AI intelligence
Wasteland.
Briefs indexed2414
Issues26
Published Mondays07:30 CT
█ Ransomware INSTITUTO-DE-CANCE 2026-09-04

INCAN Guatemala: Krybit Ransomware Halts Radiotherapy for 194 Cancer Patients

"Guatemala's national cancer institute, the Instituto Nacional de Cancerología (INCAN, formally the Instituto de Cancerología y Hospital Dr. Bernardo del Valle S., operated by the Liga Nacional Contra el Cáncer), has…"

Guatemala's national cancer institute, the Instituto Nacional de Cancerología (INCAN, formally the Instituto de Cancerología y Hospital Dr. Bernardo del Valle S., operated by the Liga Nacional Contra el Cáncer), has confirmed a cybersecurity incident that encrypted the system used to plan radiotherapy treatments and forced the suspension of sessions for approximately 194 cancer patients. The institution confirmed the incident publicly in a statement to patients and families reported by La Hora on September 1 and by Emisoras Unidas on September 2, 2026. On September 3, threat intelligence vendor DeXpose reported that the ransomware group Krybit had claimed the attack on its leak site and threatened to publish stolen data. INCAN's leadership has publicly refused to negotiate. No source has published a record count, and the institution's own statements have not confirmed that patient data was exfiltrated, so the extortion claim and the confirmed operational damage rest on different evidence.

What Happened

The timeline that emerges across Guatemalan outlets is tight. Infobae reports that staff in the Radiotherapy Department detected the failure on the morning of Monday, August 31, 2026, as they attempted to review the treatment plans scheduled for that day. Prensa Libre carries the same account from Mariluna García, head of INCAN's Radiotherapy Department, who said personnel discovered the planning system was not working correctly and subsequently found a message stating that the information had been encrypted. Both outlets report that the attackers left instructions to reach them through a deep web link in order to negotiate recovery of the data.

The system taken down holds treatment plans, prescribed doses and the imaging that radiotherapy planning depends on. Infobae reports that INCAN suspended radiotherapy, brachytherapy and superficial radiotherapy sessions while medical consultations continued on the normal schedule. Prensa Libre reports that of the roughly 194 patients under radiotherapy at the time of the attack, institute authorities estimated 5 to 10 could not tolerate an interruption and would be routed to external centers to continue treatment.

The institution's public position has been consistent but narrow. In the communiqué reported by La Hora and Emisoras Unidas, the Liga Nacional Contra el Cáncer said the Radiotherapy Department was affected by a cybersecurity incident that temporarily disrupted services, that the matter is under investigation by the competent authorities, and that administrative, medical, physics and technical teams are working continuously to restore care. Emisoras Unidas notes explicitly that the communiqué did not describe the nature of the attack or say whether patient information was affected.

Two points where accounts diverge are worth stating plainly. First, the date the institution went public: La Hora published its confirmation on September 1, while Emisoras Unidas describes the communiqué as issued on Wednesday, September 2. Second, the blast radius. La Hora reports, citing unofficial sources rather than the institution, that radiology was also hit, that MRI equipment depends on the compromised systems, and that the center had lost access to records of previously performed scans. INCAN's own statement scopes the impact to Radiotherapy. That is a single-source claim from unnamed sources and should be treated as unconfirmed until the institution or investigators address it.

On negotiation, the institution has been unambiguous. Amílcar Bravatti, vice president of the Liga Nacional Contra el Cáncer, told Canal Antigua in remarks carried by Infobae: "Como institución decidimos no proceder a la negociación y de inmediato se informó a nuestro socio proveedor de los equipos y del sistema en Estados Unidos." The refusal to pay and the immediate escalation to the US-based vendor of the affected equipment and software are the two most operationally significant decisions disclosed so far.

What Was Taken

Here the record is thin, and no one should pretend otherwise. There is no published record count, no described data taxonomy and no sample leak.

What is documented: clinical information was encrypted, per Infobae and Prensa Libre, specifically radiotherapy treatment plans, dose data and associated images. Encryption is confirmed. Exfiltration is claimed rather than confirmed.

The exfiltration claim comes from Krybit by way of DeXpose, which lists the target as INCAN at ligacancerguate.org and quotes the group's post: "The full leak will be published soon, unless a company representative contacts us via the channels provided." That is standard double-extortion posturing and appears in DeXpose's templated leak-site monitoring writeups, the same format the vendor used for its July 24 report on a Qilin claim against Kean University. Leak-site claims are marketing until proven, and DeXpose is the only source naming Krybit at all. Guatemalan press has reported the ransom demand and the deep web negotiation channel without attributing the attack to any named group.

For defenders modeling worst case, the relevant comparison is what actually surfaces when oncology data does leak. In Mexico, El Financiero reported on August 5, 2026 that the Fundación de Cáncer de Mama (FUCAM) notified breast cancer patients that full names, phone numbers and email addresses had been accessed, along with the types of radiological studies performed, radiographs, MRIs and CT scans among them. FUCAM stated that detailed medical results, radiologist reports, actual diagnostic images and financial data were not affected. In Brazil, CISO Advisor reports that the national data protection authority ANPD opened a sanction proceeding against the Instituto Saúde e Cidadania over a 2025 ransomware incident affecting roughly 500,000 patient records, including 78,772 belonging to children and adolescents and 47,921 to elderly patients, with the exposed material spanning exam histories, medical records, prescriptions, admissions, diagnoses and procedures. Those cases indicate the realistic ceiling for what a radiotherapy planning environment holds. They are not evidence about INCAN.

Why It Matters

This is an attack whose primary damage is not data loss. It is time. Radiotherapy is dose-fractionated and schedule-dependent, and the 5 to 10 patients Prensa Libre reports as unable to pause are the clearest expression of the harm: a ransomware operator's encryption routine translated directly into clinical urgency for identifiable people. Encrypting a treatment planning system is functionally an attack on the capacity to deliver care, and no backup restore is instantaneous enough to make the interruption cost-free.

The second lesson is about the target profile. INCAN is a charity-operated national referral center, not a well-funded private hospital network. Prensa Libre notes that patients travel from across the country to reach it, so a single facility's downtime becomes a national access problem with no easy substitute. Groups like Krybit are indifferent to this. The FUCAM and Isac cases show the same pattern across Latin America: cancer-focused and public-health-managing nonprofits are being worked systematically, and they are exactly the organizations least likely to have a mature detection or recovery program.

The third is the vendor dependency Bravatti disclosed. The treatment planning system and the linked equipment come from a single US-based partner, which means restoration timelines, forensic visibility and even basic questions about what the system logged are gated on a third party. That is the norm in radiation oncology, where planning software is tightly coupled to the linear accelerators it drives, and it is a structural constraint any hospital security team should have mapped before an incident, not during one.

Finally, refusing to negotiate is the right call and should be recognized as such, but it makes the leak threat live. If Krybit's claim is genuine, INCAN should expect publication and should be preparing patient notification now, rather than after the fact. The Isac proceeding in Brazil is instructive on that point: ANPD's infraction notice targets not only the failure to secure the data but the failure to notify affected individuals directly, the reliance on a vague website notice that omitted the incident date and the nature of the data, and the institution's unsubstantiated assertion that only administrative records were touched. Under-claiming impact without evidence created its own liability.

The Attack Technique

The initial access vector has not been disclosed by INCAN, by Guatemalan authorities or by any of the reporting. There is no published CVE, no named vulnerability, no phishing narrative and no indicators of compromise in circulation. DeXpose's writeup contains no IOCs, no encryptor details and no TTP analysis; it documents a leak-site listing and appends generic advice.

What can be said from the reporting is limited to observed behavior. The intrusion resulted in encryption of a clinical planning environment, a ransom note dropped where operators would find it, a demand for payment, and a Tor negotiation portal, which is the standard double-extortion playbook. Detection occurred at the point of use, when staff tried to open the system and found it broken, rather than through security monitoring. That detail matters more than the missing vector: whatever the entry point, dwell time ended when a clinician noticed, which implies little to no coverage on the clinical network segment.

Anyone claiming to know how Krybit got in is guessing. Treat any published INCAN IOC list with skepticism until it comes from the Liga Nacional Contra el Cáncer, Guatemalan authorities or the affected vendor.

What Organizations Should Do

Treat clinical planning systems as tier-zero, not medical devices someone else owns. Radiotherapy planning, PACS and dose management platforms should sit in their own segment with brokered administrative access, and their recovery time objective should be set by clinical tolerance, not by IT convention. If your RTO is longer than the interval a patient can safely skip, the RTO is wrong.

Get restoration commitments from device and software vendors in writing before you need them. INCAN's first call after refusing to negotiate was to its US supplier. Know now who your equivalent contact is, what their incident SLA is, whether they hold a clean image of your planning configuration, and whether their support model permits you to restore without waiting on a field engineer flight.

Keep offline, immutable, regularly restore-tested backups of treatment plans and dose data specifically. Backing up the file server is not the same as being able to reconstitute a planning database that a linear accelerator will accept. Test the full clinical restore path, not just the file recovery.

Instrument the clinical network so detection does not depend on a technologist opening an application. The failure mode here was discovery at point of care on a Monday morning. Endpoint telemetry on planning workstations, alerting on mass file modification, and monitoring for outbound transfers to unfamiliar destinations would each have shortened that.

Draft the patient notification before the leak, not after. If an actor has claimed exfiltration, plan for publication. The Isac case shows regulators penalizing generic website notices that omit the incident date, the categories of data involved and the remediation taken. Notify individuals directly and specifically.

Warn patients about follow-on fraud immediately. FUCAM's response to its own breach is the model worth copying: tell patients to distrust calls or messages referencing their medical studies or requesting money or banking data, to end such contact immediately, to be wary of phishing email, and to verify any purported clinic contact by calling official numbers directly. Cancer patients are an unusually high-trust, high-anxiety target set, and social engineering against them will follow any leak.

Sources: Krybit Ransomware Strikes Instituto de Cancerología, Guatemala's Pr... | Ataque cibernético golpea al instituto contra el cáncer en Guatemal... | Hackers secuestran información del Incán, exigen dinero y afectan r... | Incan confirma incidente de ciberseguridad que afecta a pacientes d... | Hackean al FUCAM: Roban datos de pacientes con cáncer de mama y est... | Qilin Ransomware Attack on Kean University - DeXpose | ANPD investiga Isac por vazamento de dados de 500 mil pacientes | Liga contra el Cáncer enfrenta incidente de ciberseguridad