On September 23, 2024, Belgian medical control and absenteeism management provider MediCheck appeared on the leak site of the ransomware group known as killsec. The listing states that internal files were exfiltrated during a ransomware attack; the exact number of affected records and the specific data types contained in those files are not detailed in the disclosure.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch medicheck.io
Get alerted the next time medicheck.io files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about medicheck.io’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Reported Details from the Listing
The killsec leak site entry, first observed on September 23, 2024, states that MediCheck suffered a ransomware incident resulting in the theft of internal files. The posting does not quantify the volume of data taken, list the precise categories of information involved, or disclose any ransom demand. It simply presents the exfiltrated material as proof of compromise and follows the group’s standard practice of publishing victim data when negotiations fail or deadlines pass. Public mirrors of the onion site, such as those indexed by ransomware.live, preserve the original claim without alteration.
Why This Matters for You and Your Family
Even though MediCheck primarily serves Belgian employers, any individual who has undergone a medical control, submitted absence documentation, or had their health-related information processed through the service may have personal details inside the stolen files. Medical and employment records are among the most sensitive categories because they combine health history, employer information, national identification numbers, and contact details in one place. When such data reaches a ransomware leak site, it becomes permanently available to identity thieves, insurance fraudsters, and blackmailers. Your family’s private health circumstances or employment status could be exposed without your knowledge, creating long-term risks that extend far beyond the original breach.
The Doxxing and Identity-Chain Risks
Stolen internal files often contain spreadsheets or databases that link employee names, email addresses, phone numbers, dates of birth, and sometimes national registry numbers. Once published, these fragments become building blocks for doxxing chains. Threat actors cross-reference the MediCheck data with other breaches to map your online handles to your real-world identity, workplace, and family members. Credential leaks of this nature frequently cascade into gaming account takeovers, especially for children whose parent accounts share the same email domain or recovery phone number listed in employment records. The public nature of the killsec posting accelerates this process because automated scrapers immediately ingest the data and feed it into underground marketplaces.