Ransomware victim disclosure
← All victimsAlcon Inc.
Claimed by Shinyhunters · listed 21 hours ago
Status timeline
- ListedAug 2, 2026
- Data leakeddate unknown
At a glance
- Group
- Shinyhunters
- Status
- Data leaked
- Country
- Switzerland
- Sector
- Healthcare
- Listed on leak site
- Aug 2, 2026
About the victim
AI dossier — public-source company profileAlcon Inc. is a global leader in innovative eye care treatments and vision products, including intraocular lenses and ophthalmic devices. The company operates internationally with a significant presence in the United States and develops life-changing vision solutions for patients and eye care professionals.
- Industry
- Ophthalmology & Eye Care Medical Devices
Attack summary
Severity: critical — Confirmed exfiltration of over 25 million records containing PII from a healthcare organization. The scale and sensitivity of personal data in a medical context, combined with the data_published disclosure status, constitutes a critical breach.The shinyhunters group claims to have compromised over 25 million Salesforce records containing personally identifiable information (PII). The group issued a deadline of 4 August 2026 for contact before threatening to publish the data.
Data the group says was taken
AI dossier — extracted from the leak post- Salesforce records
- Personally identifiable information (PII)
What the group claims
Over 25 million Salesforce records containing some PII was compromised. This is a final warning to reach out by 4 August 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline.
Sources
- Victim sitealcon.com
Source
Indexed 21 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

