Ransomware victim disclosure
← All victimsOndine Biomedical
Claimed by INC Ransom · listed 4 months ago
Status timeline
- ListedFeb 16, 2026
- Data leakeddate unknown
At a glance
- Group
- INC Ransom
- Status
- Data leaked
- Country
- Canada
- Sector
- Healthcare
- Listed on leak site
- Feb 16, 2026
About the victim
AI dossier — public-source company profileOndine Biomedical Inc. is a Canadian company founded and led by CEO Carolyn Cross. The company has developed a patented photodisinfection technology platform used in treatment and prevention therapies targeting a broad spectrum of pathogens, including multidrug-resistant strains. Its technology is not currently approved in the United States, indicating it operates primarily in non-US markets.
- Industry
- Biomedical Technology & Photodisinfection Therapeutics
Attack summary
Severity: high — The victim is a healthcare-adjacent biomedical company operating in a regulated sector; the group claims imminent full publication of all obtained data, suggesting exfiltration of potentially sensitive business, clinical, or proprietary research data. No confirmed regulated PII volume is stated, preventing a critical classification, but the sector and threatened full disclosure warrant high severity.INC Ransom claims to have compromised Ondine Biomedical Inc. and states that all obtained information will be published the following week, indicating threatened exfiltration and public disclosure of company data.
Data the group says was taken
AI dossier — extracted from the leak post- Unspecified company data pending publication
What the group claims
Ondine Biomedical Inc. is a Canadian headquartered company led by founder and CEO, Carolyn Cross. Ondine has developed a patented, photodisinfection technology platform used in treatment and prevention therapies for a broad-spectrum of pathogens - including multidrug-resistant strains. Photodisinfection, which is not currently approved in the United States We will publish all the information next week.
Source
Indexed 4 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

