Clop, the extortion group behind the MOVEit and GoAnywhere mass-theft campaigns, has added Mindray to its leak site, according to ransomware trackers that spotted the listing on August 7.
Mindray, headquartered in Shenzhen, is one of the largest medical device makers in the world. Its patient monitors, ventilators, ultrasound systems, and laboratory analyzers are deployed in hospitals across every continent, and the company counts thousands of health systems among its customers.
The claim is unconfirmed. Mindray has not issued a public statement, no stolen data has been verified, and the group has not published its usual details about the volume of files taken. Trackers that independently logged the listing include ransomware.live, HookPhish, and GalaxyWarden, which flag the entry as an unconfirmed claim.
Clop typically exploits vulnerabilities in managed file transfer platforms and then threatens to publish whatever it copied. Past campaigns hit hundreds of organizations at once, including clinical laboratories, revenue cycle vendors, and health plans, and forced downstream notification work that took months. If the Mindray claim is real, hospitals that buy or service Mindray equipment could face the same scramble to trace exposure through support tickets, service contracts, and training records.
For health systems, the practical move is the same one that followed Clop’s earlier campaigns: assume vendor data is in scope until proven otherwise, ask device vendors what records they hold on your account, and review business associate agreements for notification triggers tied to vendor-side breaches.
