On October 31, 2023, Belgian pharmacy chain MEDI-MARKET appeared on the leak site operated by the Cactus ransomware group. The listing states that internal files were exfiltrated during a ransomware attack on the company, which operates a chain of large-format health-focused stores across Belgium. The disclosure does not specify the number of people affected or list particular categories of customer or employee data.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Medimarket
Get alerted the next time Medimarket files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Medimarket’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Details in the Leak-Site Listing
The primary source, hosted on the Cactus leak portal and indexed by ransomware.live, states that MEDI-MARKET was listed after failing to meet the group’s demands. It describes the incident as a successful ransomware deployment that resulted in the theft of internal files. No sample data is shown on the public page, and the exact volume or sensitivity of the stolen material remains undisclosed by both the threat actor and the victim. The company’s public profile included in the listing notes its Brussels headquarters, €164 million in revenue, and focus on health, natural medicine, cosmetics, nutrition, and baby-care products.
October 31, 2023 marks the first public confirmation of the breach via the extortion portal. The notification does not quantify affected records, nor does it detail whether pharmacy customer prescriptions, loyalty-program information, or staff payroll files were among the stolen material.
Why This Matters for You and Your Family
When a pharmacy chain suffers a ransomware attack, the information at risk often includes details that directly affect personal health privacy and financial security. If you or your family have filled prescriptions, joined a loyalty scheme, or bought regulated products at MEDI-MARKET, your contact information, purchase history, or health-related notes may now sit in an attacker’s archive. Even without an exact victim count, the exposure creates long-term risk because health data retains value to identity thieves, insurance fraudsters, and blackmailers far longer than a simple email address.