On May 11, 2026, South Korean medical device maker Alpinion appeared on the leak site of the coinbasecartel ransomware group, with the attackers claiming to have exfiltrated internal files during a ransomware incident.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 582 companies.
See what is exposed about you — free scan →Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.
What's Publicly Reported from Reporting
Public reporting indicates that Alpinion, which develops and manufactures ultrasound imaging systems and transducers, was listed on the coinbasecartel leak site hosted on the dark web. The company, founded in 2010 as a spin-off from Samsung and headquartered in Seoul, serves healthcare providers worldwide with diagnostic solutions for radiology, cardiology, and point-of-care use. Available reporting describes the incident as a ransomware attack in which internal files were taken. The exact number of people whose information may be exposed remains unknown, and the specific types of data contained in the files have not been publicly detailed. The listing appeared on the group's onion site, accessible via links tracked by ransomware monitoring services such as ransomware.live.
Why This Matters for You and Your Family
When a healthcare technology company like Alpinion suffers a breach, the information involved often includes details that can be linked back to patients, partners, or employees. Internal files taken in ransomware attacks frequently contain contracts, employee records, vendor information, or operational data that include names, addresses, contact details, and sometimes financial or health-related identifiers. If you or your family have received care using Alpinion ultrasound equipment, interacted with a clinic that uses their systems, or if anyone in your household works in healthcare, your information could be caught up in the exposure. These incidents matter because stolen data rarely stays contained; it moves quickly through underground markets where criminals combine it with other leaks to build complete profiles.
The Doxxing and Identity-Chain Risks
A single breach rarely stops at the first company. Attackers use exposed emails, usernames, or phone numbers to locate associated accounts across the internet. This creates an identity chain that can lead to doxxing, where personal addresses, family member names, or even children's online profiles become public. Credential leaks like this one often cascade into account takeovers on email, banking, or social platforms. Gaming accounts are especially vulnerable because kids and teens frequently reuse passwords or email addresses tied to family data; a compromise at one healthcare vendor can therefore put your child's Fortnite, Roblox, or other gaming logins at risk of hijacking and subsequent harassment. Continuous monitoring across massive breach databases is one of the few practical ways to catch these linkages before harm occurs.