Falcon gang claims 2.96 TB haul from spine maker Globus Medical

Falcon says it grabbed 2.96 TB from the spinal implant maker, including FDA filings and complaint logs.

MedRisk Staff
By
2 Min Read

The Falcon extortion group says it pulled 2.96 TB of data from Globus Medical, the Pennsylvania-based maker of spinal implants and orthopedic devices. The claim, logged by ransomware trackers over the weekend, is the newest healthcare target for an operation the trackers describe as an emerging group.

Falcon’s leak-site post says the haul includes the company’s entire Microsoft PowerBI environment with more than 51,000 customer records, plus FDA feedback, 510(k) submissions, PMA approval letters, product complaint logs, serious adverse event narratives, CAPA investigation findings, merger diligence decks, FTC antitrust review documents, financial models, and board meeting minutes.

Globus Medical, traded on the NYSE as GMED, merged with NuVasive in 2023 and sells implants and surgical instruments used in spine and joint procedures across the United States and internationally. Regulatory filings inside the claimed data could carry device performance details and technical specifications, while the complaint logs and adverse event narratives describe real patient outcomes.

Ransomware.live dated the listing August 30, and RansomLook logged the same claim August 29. The victim page flags the post with a caution notice: this is an emerging group, so the claim should be treated with caution until independently verified. Globus Medical has not publicly confirmed an intrusion.

For hospital supply-chain and device-safety teams, the claim is a reminder that vendor-side breaches can expose the clinical and regulatory data underlying purchased devices. Watch for phishing attempts that cite stolen internal documents, and confirm device-related communications with Globus directly rather than through links in email.

Share This Article