Cyberattack at French hospital exposes health data of 750,000 patients

Share:

A data breach at an unnamed French hospital exposed the medical records of 750,000 patients after a threat actor gained access to its electronic patient record system.

A threat actor using the nickname ‘nears’ (previously near2tlg) claimed to have attacked multiple healthcare facilities in France, alleging that they have access to the patient records of over 1,500,000 people.

The hacker claims they breached MediBoard by Software Medical Group, a company offering Electronic Patient Record (EPR) solutions across Europe.

Softway Medical Group has confirmed that hackers have compromised a MediBoard account. However, it noted that this was not the result of a software vulnerability or misconfiguration on their part, but rather through the use of stolen credentials used by the hospital.

In a letter sent to French media and shared with BleepingComputer by LeMagIT’s editor-in-chief, Valéry Rieß-Marchive, Softway Medical Group says the exposed data was not directly managed by them, but rather hosted by the hospital.

“On November 19, 2024, a cyberattack was detected within a healthcare facility using the Mediboard software,” reads the machine-translated email.

“We want to emphasize that the affected health data were not hosted by Softway Medical Group.”

Letter

BleepingComputer contacted Softway Medical Group for clarifications on which account and at what level was compromised, and a spokesperson shared the following statement:

“We can confirm that our software is not responsible, but rather, a privileged account within the client’s infrastructure was compromised by an individual who exploited the standard functions of the solution,” the Softway Medical Group told BleepingComputer.

“This hypothesis has been substantiated. It is therefore neither due to improper implementation of the software nor human error.”

Selling access to hospitals

This all unfolded after the threat actor began selling what they claimed was access to the MediBoard platform for multiple French hospitals, including Centre Luxembourg, Clinique Alleray-Labrouste, Clinique Jean d’Arc, Clinique Saint-Isabelle, and Hôpital Privé de Thiais.

This access allegedly would let the buyer view the hospitals’ sensitive healthcare and billing information, patient records, and the ability to schedule and modify appointments or medical records.

1
Source: BleepingComputer

To prove that they gained access to the MediBoard accounts, the hacker also put the records of 758,912 patients from an unnamed French hospital up for sale.

2
Source: BleepingComputer

These records allegedly contain the following information:

  • Full name
  • Date of birth
  • Gender
  • Home address
  • Phone number
  • Email address
  • Physician
  • Prescriptions
  • Health card history

The data was offered for purchase to three users, and currently, no buyers have been declared on the sale listing.

Even if the data isn’t sold, there’s always a risk of being leaked online for free, making it available to the broader cybercrime community.

The type of data exposed in this incident raises the risk of phishing, scamming, and social engineering for impacted people.

Update 11/21: BleepingComputer has learned that all of the affected hospitals belong to a single entity, Aléo Santé, which explains how the threat actor got access to all of them by compromising one privileged MediBoard account not in Softway’s direct control.

Bill Toulas

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
12:47 pm, Jul 4, 2025
weather icon 24°C
L: 23° | H: 26°
overcast clouds
Humidity: 41 %
Pressure: 1026 mb
Wind: 9 mph WSW
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 89%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:49 am
Sunset: 9:19 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
23° | 26°°C 0 mm 0% 13 mph 42 % 1026 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
14° | 19°°C 0.97 mm 97% 13 mph 90 % 1021 mb 0 mm/h
Sun Jul 06 10:00 pm
weather icon
16° | 20°°C 1 mm 100% 10 mph 89 % 1010 mb 0 mm/h
Mon Jul 07 10:00 pm
weather icon
14° | 23°°C 1 mm 100% 13 mph 77 % 1016 mb 0 mm/h
Tue Jul 08 10:00 pm
weather icon
13° | 25°°C 0 mm 0% 9 mph 77 % 1020 mb 0 mm/h
Today 1:00 pm
weather icon
24° | 24°°C 0 mm 0% 9 mph 42 % 1026 mb 0 mm/h
Today 4:00 pm
weather icon
24° | 25°°C 0 mm 0% 12 mph 37 % 1025 mb 0 mm/h
Today 7:00 pm
weather icon
23° | 23°°C 0 mm 0% 13 mph 31 % 1023 mb 0 mm/h
Today 10:00 pm
weather icon
20° | 20°°C 0 mm 0% 10 mph 40 % 1022 mb 0 mm/h
Tomorrow 1:00 am
weather icon
19° | 19°°C 0 mm 0% 10 mph 50 % 1021 mb 0 mm/h
Tomorrow 4:00 am
weather icon
17° | 17°°C 0 mm 0% 10 mph 52 % 1019 mb 0 mm/h
Tomorrow 7:00 am
weather icon
14° | 14°°C 0.97 mm 97% 9 mph 90 % 1018 mb 0 mm/h
Tomorrow 10:00 am
weather icon
17° | 17°°C 0.7 mm 70% 10 mph 82 % 1017 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€92,668.34
-0.56%
Ethereum(ETH)
€2,169.87
-1.49%
Tether(USDT)
€0.85
0.00%
XRP(XRP)
€1.90
-2.56%
Solana(SOL)
€127.90
-2.58%
USDC(USDC)
€0.85
0.00%
Dogecoin(DOGE)
€0.141759
-3.79%
Shiba Inu(SHIB)
€0.000010
-2.90%
Pepe(PEPE)
€0.000008
-5.78%
Scroll to Top