Discovered
2026-08-30 14:29 UTC
Est. attack date
2026-08-30
Country
Sector
Agriculture and Food Production
Education
Energy & Utilities
Financial Services
Government & Defense
Healthcare
Hospitality
Manufacturing
Other
Professional Services
Retail & E-Commerce
Technology
Transportation
This is an emerging group, so this claim should be treated with caution until independently verified.
Description:
Medical devices · NYSE: GMED - Our 2.96 TB extraction includes your entire Microsoft PowerBi which contains over 51,000 records of your customers and more, FDA feedback, 510(k) submissions, PMA approval letters, TGA suspension proposals, product complaint logs, serious adverse event narratives, final CAPA investigation findings, merger diligence decks, integration plans, FTC antitrust review documents, combined P&L statements, deal models, budget spreadsheets, medical board of directors meeting minutes and agendas, executed NDAs, distribution contracts with named partners and medical institutions, patient demographics and history from clinical registries and much more.
Infostealer activity detected by HudsonRock
Compromised Employees: 12
Compromised Users: 2
Third Party Employee Credentials: 14
External Attack Surface:
10
DNS Records:
The following DNS records were found for the victim's domain.
-
us-smtp-inbound-2.mimecast.com.
Mimecast
-
us-smtp-inbound-1.mimecast.com.
Mimecast
- 6VbukFGAfludZWxJZr0SMQnNtVpD46qbNM3YXDat40YkpHTq3VXWdI4POI0FnQghpY9WhwidCEyz+bOcl7i1ZQ==
- google-site-verification=rE1rmfb7Jol9VG0mtH1884joDTtKTc4Bp4JzrRphWjY
- 3868cda6-1fd4-4749-a64a-9ffa1f9261da
- teamviewer-sso-verification=fd44eb08776540b5a97f9f3250df50f2
- smartsheet-site-validation=IsBMuxfc261n-B5MrRpCgGReit9Vgz9U
- v=spf1 ip4:184.81.91.160/27 ip4:150.105.185.150 ip4:150.105.217.150 ip4:165.193.101.141 ip4:165.193.101.49 ip4:165.193.56.42 ip4:205.217.12.155 ip4:208.2.164.108 include:us._netblocks.mimecast.com include:534679.spf01.hubspotemail.net include:spf.ltg.emai" "l include:sharepointonline.com -all
- qZG8wqJENYQNZDej9zkAK1dY7M523jhINNKJTemBjvVTaRHgG5inDnGYMUn1diC4yE+BclWhQnxhetl14jW7DQ==
- miro-verification=9f789c2fb41f3f19b8974a21c52b7d9cdefadaa0
- google-site-verification=je3EsRmP7uL2UNSXf2_8N6ouGqp2q9k7HnXb63KPJ1c
- adobe-idp-site-verification=338988647f824e49bff609f7b7c1a6046c3ad3736f1d299b0d6c007f78214b6a
- atlassian-domain-verification=E8lYBMqWEuaJG21mneCYjaIiBM8BX5GI92H0x2TPGbq1iUJ0hspG0luOc7nXFuOZ
Cloud / SaaS Services Detected
Adobe
Atlassian
HubSpot
Mimecast
Miro
Smartsheet
Teamviewer
Leak Screenshot:
Legal Disclaimer:
Ransomware.live does not engage in the acquisition, exfiltration, downloading, possession,
hosting, access, consultation, redistribution, or disclosure of unlawfully obtained data.
This platform indexes only publicly visible information posted by ransomware operators and
open web sources without accessing or obtaining the underlying stolen content.
The service is provided to support public awareness, legitimate research, and cyber-resilience.
No stolen personal or confidential data is collected or distributed via this site.