Medela (Swiss medical devices): ShinyHunters pay-or-leak → ~424k healthcare/staff contacts on HIBP (added 30 Sep)
Have I Been Pwned (added 30 September 2026; breach month September 2026) catalogues a sensitive breach for Swiss medical device company Medela (breast-pump / clinical products). HIBP states Medela was targeted in a ShinyHunters “pay or leak” extortion campaign; data later published publicly included about 424k unique email addresses (HIBP shows 423.9k affected addresses) belonging predominantly to healthcare professionals, Medela staff and sales leads. Exposed fields are primarily corporate contact data — names, physical addresses, phone numbers, email addresses, employers, job titles, salutations — with some records also carrying associated support tickets. Flagged sensitive on HIBP (not publicly searchable; verified-owner / domain dashboard only). Earlier September leak-site listing (BreachNews 6 Sep) had threatened publication without confirmed scope; HIBP 30 Sep entry is the desk’s verified catalogue primary. No AU org named. Distinct from desk shinyhunters-dutch-arrest-20260928 (arrest coverage). Primary: HIBP Medela breach page.
- Product
- Medela corporate / healthcare-professional contact and support data (not a product CVE)
- Versions
- n/a — data exposure / extortion leak (not a versioned product flaw)
- Exploited in Australia?
- unknown
- Patch to
- AU health/med-device supply chain: treat unexpected Medela/clinical-vendor contact lists as phishing fuel; force password resets only where Medela credentials were reused; HIBP sensitive — check via verified dashboard/domain monitoring rather than public search. Not a version patch.
Primary: Have I Been Pwned — Medela data breach (added 30 Sep 2026) · Vendor: Medela (vendor hub — no company incident statement cited this slot)
