Quick Summary
AllegedExecutive Summary
On September 7, 2026, metaencryptor added Hologic Inc. to its dark web portal. Hologic is a U.S.-based medical technology company specializing in women’s health diagnostics, imaging, and surgical products, with a significant global commercial footprint and an extensive partner and supplier network. The listing landed the same day SOCRadar’s Dark Web Monitoring surfaced the entry. metaencryptor claimed 10 other victims in the 60 days prior to this listing, across Healthcare, Manufacturing, and Other sectors in the United States, Canada, and Singapore. Recent U.S. healthcare and manufacturing listings include MPA Pharma GmbH, SIFCO Industries INC., FactoryFive, and Aquamar Inc. Hologic continues the group’s pattern of targeting U.S. healthcare organizations.
Technical Analysis
SOCRadar’s telemetry returned 25 records for hologic[.]com, spanning August 9 through September 6, 2026, in the three weeks immediately preceding the listing. Nine of these were employee credentials on corporate identity systems, eight were external-user records on Hologic-owned URLs, and four were corporate email addresses on third-party services. The endpoints included login.microsoftonline[.]com (Microsoft 365 tenant, with 2 @hologic.com records), login.hologic[.]com and secureauth.hologic[.]com (Hologic-owned identity portals), accounts.logme[.]in (remote-access management, with 2 @hologic.com records), bodrftp.hologic[.]com and drftp.hologic[.]com (FTP infrastructure), and partner.hologic[.]com (with 7 records, primarily a compromised supplier account). The supplier angle presents a distinct intrusion surface: 7 records on partner.hologic[.]com under a compromised supplier account indicates a separate access pathway into Hologic’s ecosystem, independent of corporate credential exposure. This suggests two potential intrusion pathways into the organization’s network. The timing of corporate credential logging in the weeks immediately surrounding a leak-site listing is consistent with infostealer-driven initial access, a known vector for metaencryptor. While the stealer-log data alone cannot confirm if these specific credentials were used by the group, the concurrent exposure of identity, SSO, remote-access, and supplier-portal information within a compressed timeframe warrants attention. Continued dark web and stealer-log monitoring is recommended, along with proactive credential hygiene checks, password rotation, and multi-factor authentication review for all corporate and supplier accounts.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.