Ransomware victim disclosure
← All victimsPoly Medicure Limited (Polymed)
listed as polymedicure.com · Claimed by INC Ransom · listed 4 months ago
Status timeline
- ListedFeb 20, 2026
- Data leakeddate unknown
At a glance
- Group
- INC Ransom
- Status
- Data leaked
- Country
- India
- Sector
- Healthcare
- Listed on leak site
- Feb 20, 2026
About the victim
AI dossier — public-source company profilePoly Medicure Limited (Polymed) is an India-based global medical device manufacturer founded in 1997. The company produces a broad range of disposable medical devices spanning infusion therapy, critical care, dialysis and renal care, cardiology, vascular access, oncology, diagnostics, anaesthesia, urology, and surgery. It markets products internationally and is listed on Indian stock exchanges as a publicly traded company.
- Industry
- Medical Device Manufacturing
- Founded
- 1997
Attack summary
Severity: high — Data has been confirmed published by the threat actor against a publicly listed medical device manufacturer operating in regulated healthcare/medical sectors; exfiltration of business-sensitive and potentially regulated data is likely given the scale of the organisation, even though specific data categories are not enumerated in the post.INC Ransom claims to have attacked Poly Medicure and has published data (disclosed status: data_published), asserting access to internal company data; no specific ransom figure or total data volume was disclosed in the post.
Data the group says was taken
AI dossier — extracted from the leak post- Internal company files
- Business documents
What the group claims
Polymed is a global leader in the medical device industry, offering a wide range of medical devices since 1997. The company specializes in various fields including infusion therapy, critical care, dialysis, cardiology, and oncology
Sources
- Victim sitepolymedicure.com
Source
Indexed 4 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

