2026 Moldova CNAM — national health insurance cyberattack; possible exfiltration disputed against “integrity intact” messaging
Data compromised
Potential personal identifiers and reimbursement or payment-linked records cited in investigative reporting; definitive field lists pending agency findings
Technical writeup
The Record and regional outlets reported that Moldova’s National Health Insurance Company (Compania Națională de Asigurări în Medicină, CNAM) acknowledged a cyberattack that may have involved theft of limited data, occurring several weeks before late-April 2026 press coverage. CNAM emphasized to broadcasters that core services continued and publicly stressed database integrity in some statements, while Moldova cybersecurity officials—in interviews summarized by Recorded Future News—suggested substantially broader exposure narratives (on the order of one-third of the agency’s sensitive database in some framings). No ransom demands were characterized in reporting. Figures remain unsettled; regulators had not finalized public denominators during initial coverage.
Root cause
Unauthorized network intrusion into national health-insurance agency systems