Quick Summary
AllegedExecutive Summary
Medela, a Swiss company specializing in healthcare products such as breastfeeding technology, neonatal care, and wound management, has been identified as a victim of the ShinyHunters extortion group. The listing was published on September 7, 2026, and was detected by SOCRadar’s Dark Web Monitoring. The group’s targeting of Medela may be influenced by its position within the sensitive healthcare sector, which often holds valuable and exploitable data. In the preceding 60 days, ShinyHunters has claimed 22 other victims, primarily targeting the Healthcare, Technology, and Financial Services sectors across the United States, Switzerland, and Israel. Medela’s listing follows similar claims made against other Swiss and healthcare-focused companies, including Alcon Inc., Elekta AB, McKesson Corporation, and NovoCure Limited, with Medela being the fifth victim identified within this specific cluster.
Technical Analysis
SOCRadar’s telemetry identified 25 records associated with the domain medela[.]com. Among these, three endpoints have been flagged as carrying an elevated risk: login.medela[.]com, brand.medela[.]com, and sec.executiveboard[.]com/executiveboard.com. The login portal hosts both corporate and consumer accounts and contained three employee records identified as Category A. The brand portal exposes both employee and external user data, while the third identified endpoint is a governance SaaS accessed by at least one Medela employee. The records span from March 2024 to September 7, 2026, and include two additional corporate email addresses found on third-party SaaS platforms and one external-user account logged on a Medela-owned system. The remaining records are consumer-facing data from the brand portal. It is important to note that the primary operational method of the ShinyHunters group involves large-scale credential abuse and social engineering, rather than relying on data obtained from infostealers for initial access. While stealer-log data revealed exposed credentials, it cannot be definitively determined if these specific credentials were used for the listing of Medela. Applying an infostealer-driven intrusion path to ShinyHunters’ activities without further corroboration could misrepresent their typical modus operandi. Organizations should consider continuous dark web monitoring, proactive credential hygiene checks, password rotation, and multi-factor authentication reviews.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.