Ransomware group falcon claims attack on Globus Medical

A criminal group has listed the US medical-device maker on its dark-web extortion site, allegedly claiming nearly 3 terabytes of sensitive company data. Globus Medical has not publicly confirmed any incident.

ThreatVectr Newsdesk· 3 min read
A global map with highlighted countries, law enforcement badges, and a broken VPN icon
Share

Key points

  • The ransomware group calling itself "falcon" listed Globus Medical on its dark-web extortion site on 30 August 2026.
  • The group's post claims it extracted approximately 2.96 terabytes of data from the company's systems.
  • Globus Medical, a US medical-device maker traded on the New York Stock Exchange under the ticker GMED, has not publicly confirmed any incident.
  • The listing was first observed by the monitoring service Ransomware.live, and the claim could not be independently verified at publication time.
  • Ransomware listings are written by criminals to pressure victims into paying; they are sometimes exaggerated or false.

What is being claimed here?

A group calling itself "falcon" has named Globus Medical on its dark-web extortion site, claiming to hold a large volume of the company's internal files. Ransomware groups, which are criminals who break into company systems and demand payment to stay quiet, run these so-called "leak sites" to pressure victims.

According to the group's post, the alleged haul runs to roughly 2.96 terabytes, which is enough storage to hold tens of millions of documents. The post describes a broad mix of internal business records, regulatory correspondence, and clinical data. Threat Vectr is not reproducing the specifics: the list was written by the attackers themselves and exists purely to frighten the company into paying.

Globus Medical is a Pennsylvania-based maker of surgical implants and related medical devices, listed on the NYSE. No public statement from the company addresses this claim.

Should patients or customers be worried?

Right now, nothing is confirmed. That matters, because acting on an unverified claim can itself be a security risk.

Criminals sometimes use news of an alleged breach to launch follow-up scams. A caller claiming to offer "breach compensation" from Globus Medical, or an email saying your data was exposed and urging you to click a link, is almost certainly a scam feeding off this listing. Ignore those approaches entirely.

A few sensible precautions cost nothing while things are unclear:

  • If you have ever had a direct account or relationship with Globus Medical, watch your inbox for phishing, which is fake email designed to trick you into handing over passwords or personal details.
  • Do not reuse the same password across multiple sites. A free password manager makes that easy.
  • Be wary of unexpected calls or texts about a data breach asking you to confirm personal information.

Should Globus Medical confirm an incident, the company would be subject to breach-notification obligations under US federal and state law, and potentially to disclosure rules under the US Securities and Exchange Commission's cybersecurity reporting requirements, which took effect for large public companies in December 2023 under 17 C.F.R. § 229.106. At that point, affected individuals would typically receive formal notice.

For now, the claim remains unverified. Threat Vectr will update this article if the company issues a public statement.

© 2026 Threat Vectr