DEV Community

Ahsan Luqman
Ahsan Luqman

Posted on Originally published at aliasfleet.com on

Medela Data Breach: What Was Leaked and What to Do Now

Swiss medical device company Medela was hit by a ShinyHunters "pay or leak" extortion campaign, and the stolen data has now been published: 423,947 accounts, including 424,000 unique email addresses, belonging mostly to healthcare professionals, Medela staff and sales leads. If you work in healthcare, check whether your work address is in it. Here is what happened and what to do.

What happened

On 7 September 2026, the ransomware group ShinyHunters listed Medela on its dark-web leak site with a "final warning", giving the company until 8 September to make contact before the stolen data would be published. The deadline passed, the data went public, and Have I Been Pwned added the breach on 30 September with 423,947 compromised accounts. HookPhish's writeup lists the same figure with the full data classes.

That is the pay-or-leak model in its plain form. There is no confirmed ransomware deployment on Medela's own systems here, and we have no verified account of how the attackers got in. What is confirmed is the output: a corporate contact dataset, published, now sitting in the hands of anyone who cares to download it.

What we do not know matters too. Medela has not issued a public statement we can find (as of know), and nobody has established the initial attack vector or how long the attackers were inside before the listing appeared. Treat anyone claiming to know those details with suspicion. The facts above are the ones on the record.

What was leaked

Per HIBP, the exposed records include:

  • Email addresses
  • Employer names
  • Job titles
  • Full names
  • Phone numbers
  • Physical addresses
  • Salutations
  • Some associated support tickets

Have I Been Pwned's Medela breach page listing the compromised data classes

No passwords or payment details were reported in this breach. That sounds reassuring until you look at what is actually dangerous in the list above. It is not the email addresses alone. It is the email addresses with job titles and employers. For comparison, the Times Car breach also exposed passwords in non-restorable form; here the risk sits in the contact data.

Why the job titles make it worse

A plain email leak gets you spam. A leak that pairs your work email with your job title and your employer gets you spear phishing.

Picture a nurse, a clinic administrator, a Medela sales rep receiving an email that knows their name, their title, where they work, and references a support ticket they actually filed. That email is not "a prince needs your help". It is an invoice from Medela, a compliance form from HR, a delivery notice from a known supplier. Healthcare workers are the audience here, and they are among the most socially engineered targets there are, because they handle purchase orders, invoices and patient logistics all day and rarely have time to scrutinise a sender.

The 424,000 addresses in this dataset are not random Gmail accounts. They are corporate inboxes, and corporate inboxes answer emails. That is the real damage curve of this breach: not what was stolen today, but what gets sent to those addresses over the next two years.

The support tickets in the dataset sharpen this further. A leaked ticket is a ready-made script: the attacker can open with a case number, a product name and a date, and the victim has no reason to doubt them, because those details are real. It is the closest thing to an inside reference a phisher can get without working there. CISA's guidance on avoiding social engineering and phishing attacks is worth a read if you want to see the playbook from the defender's side.

What to do now

If you work in healthcare, do these in order. The longer version of this checklist lives in our breach response guide.

1. Check whether you are in it. This breach is flagged as sensitive on Have I Been Pwned, which means it is not publicly searchable. Sign in to your HIBP dashboard and look under Breaches, or if you control a domain, search it there. The sign-in is free. While you are there, switch on breach notifications so the next one reaches you instead of a news article.

2. Treat Medela-flavoured mail as untrusted. Anything that looks like it comes from Medela, a supplier, or a partner referencing a support ticket gets verified through a separate channel before you click anything. Phishing thrives on familiarity, and this leak hands attackers perfect familiarity.

3. Never act on "update your account" links. Credential-harvesting mails are the most likely first wave from this dataset. If an account genuinely needs attention, go to the site yourself; the link in the email is not the way there. Report phishing attempts to the FBI's Internet Crime Complaint Center.

4. Tell your IT or security team if your work address is in it. One exposed corporate address is a personal problem; 424,000 of them inside the same industry is a sector problem. Your IT team cannot defend against what it does not know about.

5. Watch for phone and address misuse too. Phone numbers and physical addresses leaked alongside the emails. Expect unusual calls and mail, and treat unsolicited contact that uses your correct details with extra suspicion, not less.

What an email alias would have changed

This is the structural point, and it is why we write about breaches this way. Every one of those 424,000 addresses was a real inbox that Medela, its partners or its marketing stack held directly. A per-site email alias changes the arithmetic completely. Each service gets its own address; the day that address appears somewhere it should not be, it gets paused and the leak dies alone.

I run AliasFleet, which does exactly this: one alias per website, forwarding to your real inbox, killable in one click. Each alias forwards independently (the docs explain the mechanics), and the free tier covers 10 active aliases. The mechanics of aliases are explained properly in our guide on what an email alias is, and the set-up guide takes about two minutes.

An alias would not have stopped ShinyHunters from taking the data. Nothing a victim does stops the theft itself. What the alias does is contain the blast radius on the receiving end: the phishing mail arrives at an address you can name, trace and switch off, instead of your real work inbox, which you can do none of those things to. See how to tell which website leaked your email for the leak-tracing side of this.

Top comments (0)