
A major cyber attack on a software provider to healthcare organisations in France has compromised over 1.5 million patient records, including sensitive personal information of more than 750,000 individuals who visited a single hospital.
Recently, a threat actor going by the name “nears” and formerly known as ‘near2tlg’, claimed to have infiltrated MediBoard, an Electronic Patient Record (EPR) system developed by Softway Medical Group that is used by healthcare providers across Europe. The hacker claimed that they are in possession of more than 1.5 million patient data records and are willing to sell it to interested parties.
The compromised data included names, dates of birth, gender, home addresses, phone numbers, email addresses, physician details, prescription histories and health card usage information.
🚨🔴CYBERALERT, 🇫🇷FRANCE 🔴 | Un tout nouveau collectif de cybercriminels français attaque +sieurs enseignes françaises et met en vente les données sur le "Amazon de la cybercriminalité"...
Bon... il se passe actuellement une DIN-GUE-RIE en France concernant la cybersécurité !… pic.twitter.com/Hy0HFhxnN4
According to screenshots shared on X, the stolen data belonged to organisations who used MediBoard, including Centre Luxembourg, Clinique Alleray-Labrouste, Clinique Jean d’Arc, Clinique Saint-Isabelle, and Hôpital Privé de Thiais. Also, the sensitive personal data of 758,912 patients and staff of an unnamed French hospital was compromised during the incident.
The hacker added that three potential buyers have shown interest in the stolen data. There is, however, no evidence so far to ascertain that the data repository has been sold on the dark web.
Confirming the claims of “nears”, in a letter shared with the media, a spokesperson for Softway Medical Group said, “On November 19, 2024, a cyberattack was detected within a healthcare facility using the Mediboard software. We want to emphasize that the affected health data were not hosted by Softway Medical Group.
“Our software is not at fault. A privileged account within the client’s infrastructure was compromised, allowing the attacker to exploit the standard features of the solution. This is not due to software implementation issues or human error on our end,” he added.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543