Incident analysis
Samwumed was listed by Thegentlemen ransomware, a group with 1,034 victims recorded in this database. The listing appeared on the group's leak site on September 30, 2026.
Samwumed is based in South Korea and operates in the Healthcare sector. South Korea ranks #26 worldwide for ransomware disclosures, with 132 victims in this database.
Sector context. Healthcare organisations are high-value ransomware targets because patient data is extremely sensitive, regulatory penalties for breaches are severe, and operational downtime can threaten patient safety — all factors that increase ransom payment pressure.
Thegentlemen typically follows a double extortion model: data is exfiltrated from the victim's systems before files are encrypted, so the victim faces two demands at once — pay to restore access, and pay to keep stolen data unpublished. The leak site, where this listing appeared, is the lever for the second demand.