Beckman Coulter, Inc Data Breach

Alleged

Ransomware claim involving Beckman Coulter, Inc.

Published: Sep 17, 2026 MetaEncryptor
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Beckman Coulter, Inc
Industry
Business Services
Threat Actor
MetaEncryptor
Date of Incident
Sep 17, 2026

Executive Summary

Beckman Coulter, Inc, a US-based global biomedical testing and diagnostics company serving clinical laboratories and life science researchers, has been listed as an alleged victim of the MetaEncryptor ransomware group. The listing appeared on the group’s dark web portal on September 17, 2026. While this listing has not been independently confirmed as a breach, the nature of Beckman Coulter’s operations within the healthcare sector and its role in serving clinical laboratories and life science researchers could make it an attractive target for ransomware and extortion activities. The MetaEncryptor ransomware group claimed 16 victims in the 60 days preceding this listing, with a notable focus on the Manufacturing, Healthcare, and Professional Services sectors. The group primarily targets organizations in the United States, Japan, and Canada. Previous victims claimed by MetaEncryptor include Hologic, Inc., Promantra, Inc, AECOM, and SIFCO Industries INC. Beckman Coulter’s profile as a US-based healthcare company aligns directly with the threat actor’s preferred targeting demographics.

Technical Analysis

SOCRadar’s dark web monitoring detected significant exposure related to the domain beckmancoulter[.]com. The telemetry results returned 25 records, with 10 of these records directly implicating Beckman Coulter’s identity and single sign-on (SSO) infrastructure. Specifically, the exposed endpoints identified were sso.beckmancoulter[.]com and oauth.beckmancoulter[.]com, which are utilized for OpenID Connect and Keycloak-based authentication, respectively. The username profiles observed in the exposed data primarily consisted of consumer email addresses and unidentifiable handles. This pattern is consistent with a risk of customer or partner account-takeover (ATO) against the authentication layer, rather than an indicator of internal employee access. Notably, no corporate usernames ending in @beckmancoulter.com were visible within the analyzed paginated slice of data; however, this absence is not conclusive due to the limited scope of the pagination. The dominant profile emerging from this data suggests a risk of customer or supplier ATO. The retrieved data shows a freshness window between September 11, 2026, and September 15, 2026, indicating a recent and concentrated credential harvesting event. These compromised endpoints, being external-facing authentication infrastructure, are precisely the types of targets that ransomware operators and brokers actively seek after initial credential harvesting. Even without the presence of corporate usernames, this pattern strongly warrants immediate investigation. The five-day freshness window, with data harvested just nine days before the leak-site listing, is consistent with pre-operation reconnaissance activities by threat actors. Next Steps: – Audit authentication logs on sso.beckmancoulter[.]com and oauth.beckmancoulter[.]com from September 11, 2026, onward. – Extend stealer-log query to additional pages to ensure comprehensive coverage of corporate-domain credentials. – Review access patterns for any anomalous partner or customer SSO sessions.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.