A hacker using the alias 888 has advertised internal records allegedly stolen from Samsung Medison, a subsidiary of Samsung specializing in medical devices, on a cybercrime forum. The hacker claims the data was obtained through a breach of a third-party contractor and includes sensitive information such as source code, private keys, SMTP credentials, configuration files, hardcoded credentials, and personally identifiable information (PII) from a healthcare backup. The compromised data reportedly provides access to MSSQL and AWS S3 environments, with evidence suggesting backend database content, cloud storage data, SQL tables, user and employee records, internal logs, and exported cloud directories from Samsung Medison's healthcare environment. The hacker is seeking payment in Monero (XMR) and is offering the data as a one-time sale, raising significant privacy and security concerns due to the sensitive nature of the healthcare data involved.
Screenshots shared by the hacker and analyzed by security researchers indicate that the exposed data includes names, emails, country details, SQL records, and cloud logs tied to a healthcare setting, which could be misused for targeting, intrusion, or follow-up attacks. Samsung has been contacted for comment, but the authenticity of the data has not yet been confirmed. If verified, the breach could have serious implications for patient privacy and the security of medical information, especially given the potential for further exploitation or resale of the data on underground forums.

See attribution, scope, and your downstream exposure.
1 event from the most recent confirmed update back to the earliest known activity.
A threat actor was reported offering allegedly stolen Samsung Medison data for sale, with the breach said to involve a third-party compromise rather than Samsung Medison's own systems. Multiple outlets reported the same claimed sale of data on underground or dark-web forums.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.