On August 28, 2024, Vietnamese healthcare platform Medisetter.com appeared on the leak site of the ransomware group Killsec. The listing states that internal files were exfiltrated during a ransomware attack on the company, which operates Vietnam’s largest verified network of healthcare practitioners and medical students. The exact number of individuals whose information is contained in the stolen files remains unknown, as neither the leak-site posting nor any subsequent company notification has quantified affected records.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch medisetter.com
Get alerted the next time medisetter.com files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about medisetter.com’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Details from the Leak-Site Listing
The Killsec ransomware leak site, accessible via the .onion address indexed by ransomware.live, claims successful data exfiltration from Medisetter’s systems. The disclosure indicates that internal files were taken but does not specify the precise data types or volume. Public mirrors of the listing state the post date as August 28, 2024, and show that the group has not yet published any sample files or set an explicit public deadline for ransom payment in the visible entry. The platform itself focuses on verified healthcare practitioners, meaning any exposed internal files could contain professional credentials, workplace details, or contact information tied to licensed medical personnel and students.
Why This Matters for You and Your Family
When a healthcare network like Medisetter is breached, the ripple effects reach beyond the company. If you or a family member is a doctor, nurse, medical student, or even a patient whose records touch this network, your personal or professional details may now sit in an attacker’s archive. Internal files exfiltrated in ransomware incidents frequently include spreadsheets of contacts, licensing documents, email correspondence, and operational databases. Even without a confirmed record count, the exposure creates immediate risks of phishing campaigns tailored to healthcare workers and potential identity misuse that can affect household finances and reputations for years.
The Doxxing and Identity-Chain Risks
Ransomware leaks rarely stop at one dataset. A single exposed email or phone number from Medisetter’s internal files can be cross-referenced with other breaches to build a complete identity chain. This process links professional accounts to personal social media, family addresses, and children’s online profiles. Credential leaks of this nature frequently cascade into account takeovers, especially for gaming accounts belonging to your children that reuse the same passwords or recovery emails. Once attackers map these connections, targeted doxxing, harassment, or financial fraud becomes significantly easier. The healthcare focus heightens the stakes, as licensed practitioners’ details can be abused to impersonate medical professionals or launch spear-phishing attacks against clinics and hospitals.