On April 5, 2024, Israeli online medical platform Doctorim (דוקתורים) appeared on the leak site of the Malek Team ransomware group. The listing claims the attackers exfiltrated internal files containing information on more than 1,200,000 persons and companions, including verified names, identity numbers, contact numbers, emails, and phones. The group states it has destroyed all data after the successful ransomware attack.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Doctorim
Get alerted the next time Doctorim files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Doctorim’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Primary Disclosure Details
The Malek Team leak page explicitly lists Doctorim as a victim and asserts that its operators obtained more than 1.2 million records during the intrusion. The disclosure indicates the compromised material consists of internal files exfiltrated in a ransomware attack. It does not specify the exact systems breached, the volume of each data type, or whether patient medical records beyond basic identifiers were taken. The listing also claims the attackers destroyed the data after exfiltration, though no independent verification of destruction or sample files has been publicly released by the group.
Why This Matters for You and Your Family
If you or any member of your household has used Doctorim for medical appointments, prescriptions, or telehealth services in Israel, your personal details may now sit in an attacker’s archive. Verified identity numbers, names, emails, and phone numbers are the exact building blocks criminals need to open accounts, request loans, or impersonate you with government agencies and banks. Because the breach involves a medical platform, the exposure can also enable more targeted scams—fraudulent telehealth billing, fake COVID or vaccination records, or phishing calls that sound legitimate because the caller already knows your medical history. Families are especially exposed: one parent’s records often link to a spouse’s or child’s contact details, multiplying the risk across the household.
Doxxing and Identity-Chain Implications
Once names, Israeli ID numbers, and phone numbers are loose, attackers can quickly connect them to social-media handles, gaming accounts, and family addresses. A single leaked phone number can lead to SIM-swapping attempts or credential-stuffing attacks on email and banking portals. Children’s gaming accounts become easy secondary targets because parents frequently reuse passwords or security questions that appear in the Doctorim dataset. These linkages create persistent doxxing chains that can surface months or years later when another breach occurs. Continuous monitoring is the only practical way to catch these follow-on exposures before they escalate into identity theft or harassment.