Globus Medical in the US reports a ransomware incident in which threat actor Falcon allegedly exfiltrated 2.96 TB of data from its medical device-related systems, including Microsoft PowerBI records and extensive regulatory and clinical documentation such as FDA feedback, 510(k)/PMA materials, CAPA findings, and serious adverse event narratives. The claimed theft also includes merger and FTC antitrust review documents, financial and deal models, patient demographics from clinical registries, and other sensitive business and partner agreements. #UnitedStates
Incident Details
- Victim: Globus Medical
- Sector: Healthcare
- Country: US
- Actor: Falcon
- Source: http://i7loab6thvz4lb7jdr3qoeumbvilwhbgnwsctnlfmvsv7g5s3vsiw6yd.onion/#GlobusMedical
- Discovered: 2026-08-30T14:29:39.892529+00:00
- Published: 2026-08-30T00:00:00+00:00
Information
- 2.96 TB of extracted data, including the full Microsoft Power BI environment with over 51,000 customer records and more
- FDA feedback, 510(k) submissions, PMA approval letters, and TGA suspension proposals
- Product complaint logs, serious adverse event narratives, and final CAPA investigation findings
- Merger diligence decks, integration plans, FTC antitrust review documents, combined P&L statements, deal models, and budget spreadsheets
- Medical board meeting minutes and agendas, executed NDAs, and distribution contracts with named partners and medical institutions
- Patient demographics and history from clinical registries, along with additional sensitive business and regulatory documents

Disclaimer: This post is based on public claims made by the ransomware group "Falcon". I cannot confirm the accuracy of the information. However, I would be happy to share any official statement from the affected organization to provide clarification.