CSIDB logo
Incident

Centre Ellipse Strasbourg

Incident posture

Attack window
Jun 2026
Location
France
Status
Unknown
CIA posture
Available to members
Updated
2026-09-07 13:01

Linked entities

Victim
Centre Ellipse Strasbourg
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Undetermined
Discovered
Jun 2026
Disclosed
Jun 2026
Resolved
Pending

Summary

Centre Ellipse Strasbourg, an ambulatory medical facility offering personalized care pathways, was recently identified as a victim of the Akira ransomware group. The appearance of this healthcare provider in the ransomware victim list highlights the ongoing targeting of medical services by ransomware operators. No further details regarding data exfiltration, ransom demand, or mitigation steps were provided in the source.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

Centre Ellipse was identified as a victim of the Akira ransomware group in the recent victims list published on ransomware.live. The discovery was noted on 2026-06-09, with the article dated 2026-06-10 indicating the breach was reported yesterday. The entry appears under the “Recent Victims” section alongside other organizations affected by various ransomware strains. Akira is a ransomware operation known for targeting multiple sectors across different geographic regions. The listing includes a brief descriptor of the victim’s nature and location. No additional technical details about the attack vector, encryption methods, or ransom demand are provided in the source material.

Centre Ellipse is described as an ambulatory medical facility located in Strasbourg. The facility offers personalized care pathways to its patients, focusing on individualized treatment approaches. The source does not specify the size of the organization, the number of patients served, or the specific services beyond the personalized care mention. No information is given about data exfiltration, system downtime, or any response actions taken by the facility following the discovery. Consequently, the narrative is limited to the confirmed facts of the victim’s identity, the ransomware group involved, the discovery date, and the facility’s general description.

Sources

Sources available to members: 1 source.

CSIDB