On February 14, 2025, medical device manufacturer COSMED appeared on the leak site of the Akira ransomware group. The attackers claim to have stolen more than 25 GB of internal corporate documents, including passport scans, NDAs, confidential files, financial audits, payment details, reports, and foreigner identity cards. Anyone whose personal information appears in those files — employees, contractors, business partners, or their families — now faces heightened risk of identity theft and doxxing.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Cosmed
Get alerted the next time Cosmed files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Cosmed’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting indicates that COSMED, a privately owned company that produces cardiopulmonary, metabolic, and body composition diagnostic equipment, was listed by the Akira group on its data-leak portal. The posting states the attackers exfiltrated more than 25 GB of documents containing sensitive personal and corporate information. No exact number of affected individuals has been confirmed, and the company has not yet issued a public statement detailing the scope or timeline of the breach. Available reporting describes the exposed materials as including passport scans, signed NDAs, financial records, payment details, and identity cards for foreign nationals.
Why This Matters for You and Your Family
When a company that handles medical, financial, or travel documents is breached, the information rarely stays contained. Passport scans and identity cards can be used to open accounts in your name, apply for credit, or create fraudulent identities. Financial audits and payment details often contain enough context to make phishing attempts more convincing. If you or a family member ever worked with COSMED, received services from them, or had documents shared during a business relationship, your data could now be in attackers’ hands. Children’s information linked to a parent’s work records can also be exposed, creating long-term risks that grow as they reach adulthood.
The Doxxing and Identity-Chain Implications
Credential leaks and document dumps rarely stop at one incident. A single passport scan can be cross-referenced with email addresses, phone numbers, or gaming usernames found in other breaches. Attackers chain these fragments together to build complete profiles, leading to account takeovers, targeted phishing, or public doxxing. Gaming accounts belonging to you or your children are especially vulnerable because the same passwords or recovery emails are often reused across work, personal, and entertainment platforms. Once one account falls, the rest can follow in rapid succession.