Doctorim Listed by malekteam Ransomware Group
If you are a customer of Doctorim, here’s what is being claimed, and what it would mean for you.
🔥"Doctorim" ,in Hebrew "דוקתורים" ,is the online medical site in Israel which attacked by Malek teambased on this successful cyber attack, we have the information of more than 1,200,000 persons and companions ☠️information includes: ☠️🩸 verified names🩸 verified identity numbers,🩸 verified contact numbers🩸 verified emails & phones🩸 & etc ...🧨⚠️and we destroyed all data⚠️🧨 MALEK TEAM has everything 🔪🩸
— from Malekteam’s own leak-site posting. This is the group’s claim, quoted verbatim; it is not GalaxyWarden’s reporting and has not been independently verified.
Editor’s note: The claims described below originate from a ransomware group’s leak-site posting and have not been independently verified by GalaxyWarden. A listing of this kind is an assertion made by the group during an extortion attempt. It is not evidence that a breach occurred, and we report it as a claim rather than as a finding.
Doctorim customer?
See what’s already exposed about you — free, 15sWe check your email against known public breach records and the sites that publish your address, then show you what to do about each one. We don’t hold this company’s data. No account, no card.
On April 5, 2024, Israeli online medical platform Doctorim (דוקתורים) appeared on the leak site of the Malek Team ransomware group. The listing claims the attackers exfiltrated internal files containing information on more than 1,200,000 persons and companions, including verified names, identity numbers, contact numbers, emails, and phones. The group states it has destroyed all data after the successful ransomware attack.
Primary Disclosure Details
The Malek Team leak page explicitly lists Doctorim as a victim and asserts that its operators obtained more than 1.2 million records during the intrusion. The disclosure indicates the compromised material consists of internal files exfiltrated in a ransomware attack. It does not specify the exact systems breached, the volume of each data type, or whether patient medical records beyond basic identifiers were taken. The listing also claims the attackers destroyed the data after exfiltration, though no independent verification of destruction or sample files has been publicly released by the group.
Why This Matters for You and Your Family
If you or any member of your household has used Doctorim for medical appointments, prescriptions, or telehealth services in Israel, your personal details may now sit in an attacker’s archive. Verified identity numbers, names, emails, and phone numbers are the exact building blocks criminals need to open accounts, request loans, or impersonate you with government agencies and banks. Because the breach involves a medical platform, the exposure can also enable more targeted scams—fraudulent telehealth billing, fake COVID or vaccination records, or phishing calls that sound legitimate because the caller already knows your medical history. Families are especially exposed: one parent’s records often link to a spouse’s or child’s contact details, multiplying the risk across the household.
Advertisement
BATECH StudioWe build it.We run it.Web apps, AI pipelines and internal tools — under your brand, not ours.Tell us what you need →
BATECH Studio and GalaxyWarden share common ownership.
Doxxing and Identity-Chain Implications
Once names, Israeli ID numbers, and phone numbers are loose, attackers can quickly connect them to social-media handles, gaming accounts, and family addresses. A single leaked phone number can lead to SIM-swapping attempts or credential-stuffing attacks on email and banking portals. Children’s gaming accounts become easy secondary targets because parents frequently reuse passwords or security questions that appear in the Doctorim dataset. These linkages create persistent doxxing chains that can surface months or years later when another breach occurs. Continuous monitoring is the only practical way to catch these follow-on exposures before they escalate into identity theft or harassment.
Malek Team’s Known Track Record
Public reporting attributes the emergence of Malek Team to late 2023. The group has focused primarily on Israeli and Middle Eastern targets, listing healthcare providers, educational institutions, and small-to-medium businesses. Its typical playbook begins with initial access gained through phishing or exploited remote desktop services, followed by exfiltration of internal documents and databases. The group then deploys ransomware and, if unpaid, publishes victim names on its leak site while claiming to have destroyed the stolen data. Past listings have followed a similar pattern of bold claims paired with limited proof, yet the released contact and identity information has proven accurate enough to cause real harm to affected individuals.
What to do
- Run a DoxxScan to map every link between your handles, emails, phone numbers, and real identity, including cleanup of exposed records.
- Rotate any password you used on Doctorim or any Israeli medical site and enable 2FA through an authenticator app everywhere that password was reused.
- Enable continuous DoxxScan monitoring across 13.1B+ breach records and 100+ platforms so the next exposure of your data is caught in hours rather than months.
- Cover the household with DoxxScan family protection that extends to dependents and children’s gaming accounts that often chain back to the same leaked address or phone number.
- Let remediation specialists handle takedown requests across data brokers and threat platforms on your behalf.
The Doctorim breach demonstrates how quickly medical-sector intrusions turn into long-term identity risks for ordinary families. One timely scan and ongoing vigilance can break the chain before criminals exploit the 1.2 million records now in circulation. DoxxScan by GalaxyWarden delivers that continuous monitoring across 13.1 billion+ breach records and more than 100 platforms, AI-powered identity-chain mapping, hands-on remediation by specialists, and full household coverage that includes children’s gaming accounts. Start your DoxxScan trial today and close the gaps this incident has opened.
What the free scan actually returns
Found on people-search siteswe remove these
These listings are live, public, and legal to remove — and removing them is what we do.
Found in breach recordsverifiedreported — unverified
Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.
Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.
For security and vendor-risk teams: a staff address in a leak does not mean you were breached — it usually means a third party was. We monitor a domain against 13.1B+ leaked records and tell you when one of your people appears. See what we would check →
Report details & sourcing
Related breaches
Integrated Health Systems Listed by coinbasecartel Ransomware Group
Integrated Health Systems was listed on the coinbasecartel ransomware leak site. The group claims to…
Flecha Bus Listed by coinbasecartel Ransomware Group
Flecha Bus is an Argentine intercity bus company operating in the passenger transportation industry.…
Kessler Creative Listed by coinbasecartel Ransomware Group
Kessler Creative was listed on the coinbasecartel ransomware leak site. The group claims to have sto…