// UNCLASSIFIED // CLEARED FOR PUBLIC RELEASE //
FILE BRC-hibpDTG 0600Z
Breach Record

Medela

DISCLOSED 2026-09-07 · STOLEN CREDS · 423,947 RECORDS EXPOSED

In September 2026, Swiss medical device company Medela was the target of a ShinyHunters "pay or leak" extortion campaign. The data allegedly obtained in the breach was later published publicly and included 424k unique email addresses belonging predominantly to healthcare professionals, Medela staff and leads. The exposed data consisted primarily of corporate contact...

The record

What we know

Disclosed
2026-09-07
Attack vector
Stolen Creds
Records exposed
423,947
Domain
medela.com
Data classes exposed
Email addressesEmployersJob titlesNamesPhone numbersPhysical addressesSalutationsSupport tickets
Sources

Cited reporting

Similar vector · recent

Other stolen creds breaches on file

This page is the permanent ColdRecon entry for the Medela disclosure. It updates if new public reporting emerges. All tracked breaches →

Medela just lived through this. Your next prospect doesn't have to.

ColdRecon turns every disclosed breach into a daily intelligence brief from the seller's seat — normalized to the factors that move a deal, written in the Handler's voice. Request clearance and the first lands tomorrow at 0600.

Request Clearance →