Medela: a data breach
In September 2026, Swiss medical device company Medela was the target of a ShinyHunters "pay or leak" extortion campaign . The data allegedly obtained in the breach was later published publicly and included 424k unique email addresses belonging predominantly to healthcare professionals, Medela staff and leads. The exposed data consisted primarily of corporate contact information, including names, physical addresses and phone numbers, with some records also containing associated support tickets.
The record
- Organisation
- Medela →
- Identity
- Medelaidentified by its domain in a verified breach record
- Records affected
- 423,947 records
- Data exposed
- Email addresses, Employers, Job titles, Names, Phone numbers, Physical addresses, Salutations, Support tickets
- Sector
- Not recorded
- Occurred
- 2026-09-07
- Disclosed
- 2026-09-30
- First recorded here
- 2026-09-30
Fastnexa security experts
Worried the same could happen to your company?
If you are a customer or supplier of Medela, or work in the same industry, a Fastnexa security expert can tell you what this means for your data and test whether the same attack would work on you.
Think you’ve already been hit? Don’t wait on a form: call or WhatsApp +1 (732) 454 2616. We reply within 1 hour, 24/7. Emergency help →
Sources (1)
One source so far.
- Have I Been Pwned ↗First reported
2026-09-30