ShinyHunters Names Medela in Data Breach and Extortion Claim

ShinyHunters has named medical device company Medela as an alleged victim and is threatening to publish purportedly stolen data if it does not engage.
ShinyHunters data leak site listing Medela as an alleged victim with a Sept. 8, 2026 deadline and threat to leak data.
ShinyHunters added Medela to its data leak site, threatening to publish allegedly stolen data and cause additional digital disruption if the company does not engage by Sept. 8.

ShinyHunters has named global medical device company Medela as its latest alleged victim, threatening to publish purportedly stolen data if the company does not engage with the group.

The Sept. 6 listing describes the post as a “final warning” and gives Medela until Sept. 8 to make contact. ShinyHunters also threatens unspecified additional digital disruption alongside the potential data release.

Unlike some of the group’s recent breach claims, however, ShinyHunters has not disclosed what it allegedly stole from Medela, how much data may be involved, or how the company was purportedly compromised. No samples or other evidence establishing the scope of the claimed intrusion accompanied the listing reviewed by BreachNews.

Medela had not issued any public statement confirming the ShinyHunters claim at time of publication.

Healthcare sector remains in ShinyHunters’ sights

The Medela claim is notable given ShinyHunters’ recent activity against healthcare and medical technology organizations.

Medela develops breast milk feeding and baby products alongside medical technology used in maternity, neonatal intensive care, wound care and surgical settings. The company says it has approximately 1,500 employees across 20 subsidiaries and reaches more than 14 million mothers, babies, patients and healthcare professionals annually.

ShinyHunters has recently named several other healthcare-related organizations as alleged victims. In August, the group targeted McKesson, Neogen, Jack Henry and Elekta in another series of breach claims, similarly using deadlines and threats of data publication to pressure the companies.

The Medela listing continues that extortion strategy. Rather than immediately publishing purportedly stolen information, ShinyHunters is using the threat of a future leak and additional disruption as leverage while publicly setting a deadline for the alleged victim.

Health sector warned about active ShinyHunters campaigns

The claim also arrives days after Health-ISAC issued an urgent threat alert warning that ShinyHunters-linked activity is actively targeting the global health sector.

Health-ISAC said recent campaigns have relied heavily on voice phishing and malicious impersonation domains to obtain employee credentials. In several observed incidents, attackers reportedly bypassed multi-factor authentication before moving from compromised single sign-on accounts into connected SaaS applications and exfiltrating data for extortion.

Earlier Health-ISAC guidance described a recurring attack chain involving social engineering, identity compromise, SSO account takeover and subsequent access to cloud applications. There is currently no evidence establishing that this technique was used against Medela, and ShinyHunters has not disclosed an alleged initial access method for the company.

What happens after the Sept. 8 deadline

ShinyHunters’ listing leaves the most important questions unanswered. The group has not identified the systems allegedly accessed or said whether customer, employee, corporate or healthcare-related information was affected.

The Sept. 8 deadline could provide the next indication of the claim’s credibility. ShinyHunters has threatened to publish data if Medela does not engage, which could provide additional information about the alleged intrusion and its potential impact.

Until then, the existence and scope of any Medela compromise remain unconfirmed.

BreachNews will update this report if Medela confirms an incident, ShinyHunters publishes allegedly stolen data, or additional evidence establishes the scope of the claimed breach.

Picture of m00s3c

m00s3c

Moose (@m00s3c) is the author of BreachNews, focusing on data breach intelligence, dark web monitoring, and threat analysis. His work involves analyzing breach claims, reviewing leaked datasets, and tracking threat actor activity to provide clear, factual reporting.

Latest News

BREACHNEWS.COM/SUPPORT/

Support Independent News.

Help support breach monitoring, investigations, infrastructure, and reporting.

Support the site