Medela Breach: 424K Healthcare Contacts Leaked (2026)
In September 2026, Swiss medical device company Medela was the target of a ShinyHunters "pay or leak" extortion campaign . The data allegedly obtained in the breach was later published publicly and included 424k unique email addresses belonging predominantly to healthcare professionals, Medela staff...
Overview
Medela, the Swiss medical device manufacturer best known for breast pumps and pumping accessories, was targeted in September 2026 by a ShinyHunters extortion campaign. The gang gave Medela a choice: pay, or watch the data go public. Medela did not pay. The data went public.
The leaked dataset contains 423,947 unique email addresses, most of them belonging to healthcare professionals, Medela employees, and sales leads. The records are corporate contact information rather than clinical or financial data: names, physical addresses, phone numbers, and email addresses, with some entries including associated support tickets. The breach has since been added to Have I Been Pwned, making it searchable by anyone.
Anyone who works in healthcare procurement, lactation consulting, hospital supply chain management, or who has contacted Medela for support in recent years could appear in this file.
What Was Exposed
Every leaked record centers on an email address treated as a unique identifier. Alongside those emails, the dataset includes:
- Names - full names tied to each contact record.
- Phone numbers - direct or switchboard lines, sometimes both.
- Physical addresses - corporate offices, clinics, and possibly home addresses for remote staff.
- Support ticket references - some records link contacts to specific inquiries.
No passwords, payment cards, or Social Security numbers appear in the leak. That distinction matters: this is not a credential-stuffing windfall. It is a targeted contact list.
Why Contact Data Is Worth Stealing
A list of 424,000 verified healthcare professionals is a phishing goldmine. Attackers can cross-reference job titles with known medical distributors, hospital systems, and Medela’s own product line to craft convincing pretexts. A fake “Medela recall notice” or “order confirmation” sent to a verified address and phone number clears the first hurdle of suspicion.
Because support ticket ties are included, some records reveal who asked about what - a secondary intelligence layer that helps attackers personalize follow-up attempts.
Who’s Actually Affected
The headline number understates the spread. A single Medela contact record may belong to:
- Hospital procurement officers who never bought a Medela product.
- Lactation consultants listed as referral partners.
- Third-party distributors with shared CRM records.
- Medela staff whose work emails appear in daily operations.
If your address is in this file, you were not necessarily a Medela customer. You were simply in their pipeline.
What to Do Right Now
- Check the breach. Visit haveibeenpwned.com/Breach/Medela and search your work and personal email addresses.
- Treat unexpected Medela emails with suspicion. Verify sender domains carefully - lookalikes like
medela-support.comare trivial to register. - Expect voice phishing. Your number is public now. If someone calls claiming to be from Medela or a partner distributor, hang up and call back on a number you look up yourself.
- Warn your IT and security team. If you handle procurement or clinical supplies, your colleagues are likely in the same file. A short internal advisory prevents the whole department from falling for the same lure.
- Freeze your data exposure profile. Opt out of people-search sites that may now scrape this leak and surface your corporate address alongside your name.
Security Insight
ShinyHunters did not breach Medela’s clinical systems or manufacturing lines - they walked away with a contact database, likely sitting in a CRM, marketing platform, or support ticketing tool. That is the uncomfortable lesson: the highest-value asset in a medical device company’s attack surface may be a sales pipeline spreadsheet nobody thinks to protect with the same rigor as patient data. Compare this to the wave of healthcare breaches where ransomware crews encrypt hospital records; here the harm is slower, quieter, and delivered one phishing email at a time. Medela’s refusal to pay was the right call, but it exposed hundreds of thousands of healthcare workers to targeted social engineering. The industry needs to treat verified contact lists as sensitive infrastructure, not marketing collateral.
Further Reading
Never miss a data breach report
Get real-time security alerts delivered to your preferred platform.
Related Breach Reports
In August 2026, the French intellectual property software and services company Questel was the target of a ShinyHunters "pay or leak" extortion campaign . The group subsequently published an extensive corpus of data they alleged was obtained from the company, largely comprising corporate contact inf...
In July 2026, the cloud-based business communications platform RingCentral was the target of a ShinyHunters "pay or leak" extortion campaign . The group subsequently published data they claimed was obtained from the platform, which included 1.6M unique email addresses along with names, physical addr...
In August 2026, the Alcon eye care company was named in a ShinyHunters "pay or leak" extortion campaign . The group subsequently published data allegedly sourced from Alcon containing 218k unique email addresses along with other largely corporate B2B contact fields, including name, phone number and ...
In June 2026, Inter-Con Security was targeted in a ShinyHunters “pay or leak” extortion campaign . The group subsequently published data it alleged was taken from the company, including 276k unique email addresses along with names, physical addresses, job titles and phone numbers. The data encompass...