Ransom! Globus Medical (AUG-2026)

Globus Medical in the United States reported a Falcon ransomware incident targeting medical device related Microsoft Power BI data, claiming the extraction of 2.96 TB including sensitive records such as customer data, FDA and 510(k)/PMA materials, adverse event narratives, CAPA investigation findings, and distribution and merger diligence documents. The stolen/compromised data is alleged to include regulatory, clinical, and corporate records related to patient demographics and histories, ending with #UnitedStates.

Incident Details

  • Victim: Globus Medical
  • Sector: Healthcare
  • Country: US
  • Actor: Falcon
  • Source: http://i7loab6thvz4lb7jdr3qoeumbvilwhbgnwsctnlfmvsv7g5s3vsiw6yd.onion/#GlobusMedical
  • Discovered: 2026-08-30T14:29:39.892529+00:00
  • Published: 2026-08-30T00:00:00+00:00

Information

  • 2.96 TB of extracted data includes a full Microsoft Power BI environment with over 51,000 customer records.
  • Sensitive regulatory and compliance documents were exposed, including FDA feedback, 510(k) submissions, PMA approval letters, and TGA suspension proposals.
  • Product and safety records were included, such as complaint logs, serious adverse event narratives, and final CAPA investigation findings.
  • Corporate transaction and strategy materials were compromised, including merger diligence decks, integration plans, and FTC antitrust review documents.
  • Financial and operational documents were also taken, including combined P&L statements, deal models, and budget spreadsheets.
  • Internal governance materials were exposed, such as medical board meeting minutes and agendas, along with executed NDAs.
  • Commercial agreements and partner records were included, such as distribution contracts with named partners and medical institutions.
  • Clinical registry data was also compromised, including patient demographics, medical history, and related clinical records.

Disclaimer: This post is based on public claims made by the ransomware group "Falcon". I cannot confirm the accuracy of the information. However, I would be happy to share any official statement from the affected organization to provide clarification.

monitored by: ransomware.live