On December 6, 2025, healthcare provider Woundtech appeared on the leak site of the ransomware group fulcrumsec. The company, which delivers in-home and facility-based wound care to Medicare and Medicaid patients across the United States, had internal files exfiltrated during a ransomware attack. While the exact number of affected individuals remains unknown, anyone whose medical records, insurance details, or personal information passed through Woundtech could now be exposed.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Woundtech
Get alerted the next time Woundtech files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Woundtech’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting indicates that fulcrumsec listed Woundtech on its dark-web leak site and claims to have stolen internal company files. The data includes documents generated in the course of delivering specialized wound care to patients in skilled nursing facilities and private homes. No confirmed samples of patient records have been independently verified in open sources, but the group’s standard practice is to publish proof of exfiltration when victims do not pay. The incident fits a pattern of attacks on mid-sized healthcare organizations that handle sensitive protected health information.
Why This Matters for You and Your Family
If you or a family member received wound care from Woundtech, your medical history, insurance numbers, addresses, and contact details may now sit on a ransomware leak site. Healthcare breaches expose information that cannot be changed like a password: once your Social Security number, date of birth, or diagnosis details are public, they remain valuable to identity thieves for years. Families relying on Medicare or Medicaid are frequent targets because government insurance records often link multiple generations at the same address. A single leak can give criminals enough data to file fraudulent tax returns, open new accounts, or pressure you with threats of releasing private medical information.
The Doxxing and Identity-Chain Risk
Stolen healthcare files rarely stay isolated. Attackers combine medical data with credentials from other breaches to build detailed profiles. An email address listed in Woundtech records can be matched to gaming accounts, social-media handles, or family-shared passwords. This creates an identity chain that leads directly to you and your children. Credential leaks like this one frequently cascade into account takeovers on Steam, Roblox, or Discord, where children’s usernames and chat logs are then used to expand the doxxing file. The result is not just identity theft but targeted harassment that can affect every member of the household.