The Clop extortion gang listed Philips and Starkey on its dark web leak site on August 12, adding two major health technology names to a large batch of new victims. Trackers logged the Philips entry at 16:23 UTC and the Starkey entry one minute earlier, part of a wave that also included GE, Fiserv, and the Aldo Group.
Philips, the Dutch multinational that builds medical imaging systems, patient monitoring equipment, and personal health products for hospitals in more than 100 countries, is the most consequential healthcare target. Ransomware.live shows an estimated attack date of August 12, and Hudson Rock data tied to the domain lists 413 compromised employee credentials in infostealer logs, suggesting a long-running exposure of staff logins. Starkey, the privately held hearing aid maker based in Eden Prairie, Minnesota, builds AI-powered hearing devices with health monitoring features.
Neither company has publicly confirmed the claim, and leak site listings are frequently exaggerated or fabricated. Clop has a history of mass-listing victims after exploiting file transfer software flaws, and the same-minute timing of these entries points to a coordinated disclosure.
For hospital security teams, the practical step is credential review. Compromised employee credentials are a known Clop entry point, so organizations with Philips or Starkey systems should hunt for suspicious logins tied to those vendors, watch for phishing built around the claims, and treat any unsolicited extortion email as high priority.
