Ransomware victim disclosure
← All victimsCook Medical LLC
Claimed by Shinyhunters · listed 4 days ago
Status timeline
- ListedAug 14, 2026
- Data leakeddate unknown
At a glance
- Group
- Shinyhunters
- Status
- Data leaked
- Country
- United States
- Sector
- Healthcare
- Listed on leak site
- Aug 14, 2026
About the victim
AI dossier — public-source company profileCook Medical is a manufacturer of minimally invasive medical devices across multiple specialties including vascular intervention, interventional radiology, endoscopy, urology, and critical care. The company designs and distributes medical devices to healthcare systems globally.
- Industry
- Medical Devices & Healthcare
Attack summary
Severity: critical — Confirmed exfiltration of customer and employee data at significant scale (182GB+) from a regulated healthcare company. Healthcare sector data involves sensitive PII and potentially protected health information subject to HIPAA and similar regulations.ShinyHunters claims to have exfiltrated customer data, employee data, and internal corporate data totaling 182GB (compressed). The group states negotiations occurred but broke down over ransom demands, leading to the data publication.
Data the group says was taken
AI dossier — extracted from the leak post- customer data
- employee data
- internal corporate data
What the group claims
Customer data, employee data, and other internal corporate data was compromised. The Company engaged with us but made several paltry offers, did not want to pay what we asked for and decided they are okay with the data leak to happen instead of increasing their offer by a little, then we'd likely have accepted and this post would not have gone up. The Company failed to reach an agreement with us despite our incredible patience, all the chances and offers we made. They don't care. | Size: 182GB+ (compressed) | Updated: 14 August 2026 | SHA256: 8a87ba511f25f20a193f05a6578a620b02302c2075a6f2dff428d1f1a826ba63
Sources
- Victim sitecookmedical.com
Source
Indexed 4 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

