Ransomware victim disclosure
← All victimsXpress Nebs (Pediatric Products, LLC)
listed as xpressnebs.com · Claimed by Lockbit5 · listed 4 months ago
Status timeline
- ListedFeb 23, 2026
- Data leakeddate unknown
At a glance
- Group
- Lockbit5
- Status
- Data leaked
- Country
- Germany
- Sector
- Healthcare
- Listed on leak site
- Feb 23, 2026
About the victim
AI dossier — public-source company profileXpress Nebs, operating as Pediatric Products, LLC, is a JCAHO-certified Durable Medical Equipment company based in Cincinnati, Ohio. The company specializes in supplying nebulizers, compressors, and accessories to the pediatric respiratory community across Ohio, Indiana, Kentucky, Arkansas, West Virginia, and Tennessee. It operates a clinic-stocking program allowing immediate distribution of respiratory equipment at the point of diagnosis.
- Industry
- Durable Medical Equipment (Pediatric Respiratory)
- Address
- 2975 Exon Avenue, Cincinnati, OH 45241
Attack summary
Severity: critical — The victim is a JCAHO-certified DME healthcare provider handling pediatric patient data (PHI), which is regulated under HIPAA. The disclosed status is 'data_published', meaning sensitive regulated health data has been exfiltrated and published, constituting a critical breach of regulated medical information at scale.LockBit 5 claims an attack against Xpress Nebs with data published status, indicating exfiltration and likely publication of stolen data. Given the company's healthcare focus serving pediatric patients, the compromised data is expected to include protected health information and related patient records.
Data the group says was taken
AI dossier — extracted from the leak post- Patient health information (PHI)
- Pediatric patient records
- Insurance/billing records
- Business operational data
- Employee/staff information
- Physician and clinic contact data
What the group claims
Xpress Nebs is a JCAHO certified Durable Medical Equipment company that specializes in providing hig...
Sources
Source
Indexed 4 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

