Blog

Medela Data Breach Exposes Nearly 424,000 Accounts

Written by doudou - September 30, 2026

← All articles

What Happened to Medela?

A data breach involving Swiss medical device company Medela has raised new concerns about the security of professional and customer information. The incident was reported on September 30, 2026, after a database linked to Medela was added to Have I Been Pwned.

According to the information available, around 423,947 accounts were affected. The exposed information reportedly included professional email addresses, names, employers, job titles, phone numbers, physical addresses and information contained in some customer support tickets.

The incident has been associated with ShinyHunters, a cybercriminal group known for data theft and extortion campaigns. However, it is important to distinguish between information that has been independently documented and claims made by the attackers themselves. The exact way the attackers initially gained access to Medela's systems has not been publicly established.

What happened to Medela?

The incident became public earlier in September, when ShinyHunters reportedly listed Medela as a victim on its data leak platform. The group claimed to have obtained information belonging to the company and threatened to release it if its demands were not met.

The situation later escalated when the allegedly stolen data became available online. On September 30, the database was added to Have I Been Pwned, which listed 423,947 affected accounts.

The number is significant, but it does not necessarily mean that every person associated with those accounts had all of their personal information exposed. The figure represents the number of accounts or email addresses contained in the leaked dataset.

What kind of information was exposed?

The leaked information appears to contain a mixture of professional and personal data. This includes email addresses, names, employers, job positions and phone numbers. Some records also reportedly contained physical addresses and information from customer support interactions.

At first glance, some of this information might not seem particularly sensitive. An email address or job title, for example, may already be publicly available. The problem comes when attackers combine several pieces of information together.

Knowing someone's name, company, position and contact details can make a phishing email look much more convincing. An attacker could potentially pretend to be a colleague, an IT employee or a trusted business partner.

Support tickets can make this even more useful for attackers because they may contain additional context about a person's interactions with a company or its technical environment.

Why is this important?

Data breaches are not only about passwords and credit card numbers. Information that appears harmless on its own can become valuable when it is combined with other data.

For example, an attacker who knows that a particular employee works in IT and has previously contacted a company's support team could create a highly targeted phishing message. The message could refer to a real problem, a real department or a legitimate service, making it much harder for the victim to recognize the attack.

This type of information can also be used in social engineering campaigns. Instead of sending thousands of generic messages, attackers can use leaked information to make a much smaller number of highly targeted attempts.

The role of ShinyHunters

ShinyHunters has become known for campaigns involving stolen data and extortion. Its approach generally involves gaining access to information, threatening to publish it and putting pressure on the targeted organization.

The group has been connected to several major data theft campaigns, making it a significant name in the cybercrime ecosystem.

In September 2026, Google and Mandiant also reported activity associated with ShinyHunters targeting organizations using Oracle PeopleSoft. The victims reportedly included organizations from several sectors, including healthcare, education, government and technology.

The Medela incident therefore happened during a period of broader activity attributed to the group.

What should affected users do?

For people whose information may have been included in the breach, one of the main concerns is the possibility of targeted phishing attacks.

An unexpected email asking for a password, authentication code or sensitive information should be treated carefully, especially if it appears to come from a colleague or a company's IT department.

Users should also avoid reusing passwords between different services and should enable multi factor authentication whenever possible. Even when a leaked database does not contain passwords, attackers can use exposed personal information to make future attacks more convincing.

A reminder that personal data can be valuable

The Medela incident is another example of how valuable professional information has become to cybercriminals.

A leaked email address may seem relatively harmless. When combined with a person's name, employer, job title and previous support interactions, however, it can provide attackers with enough information to build a convincing social engineering campaign.

With nearly 424,000 accounts reportedly included in the leaked dataset, the Medela incident highlights the importance of protecting not only passwords and financial information, but also the everyday professional data that companies collect and store.

At the same time, some details surrounding the incident remain unclear. The existence of the leaked dataset is documented by Have I Been Pwned, but the precise method used to gain access to Medela's systems has not been publicly confirmed. For now, claims made by ShinyHunters should therefore be treated separately from independently verified information.

Privacy Policy Terms © 2026 Vulpine. Your acts, your responsibility.