Skip to content

MedCred Dataset Claim Lists 274,534 Users With Names, Email and Address Information

Data Exposure Report Ireland flagIreland Healthcare Credentialing Contact & Location Data Download Listing Unverified

MedCred Dataset Claim Lists 274,534 Users With Names, Email and Address Information

Claimed users274,534
Compressed size4.6 MiB
Raw size18.6 MiB
Unlock cost8 points

An actor using the handle "replaceboundless" claims to have uploaded a MedCred dataset for download. The listing describes MedCred as an Ireland-based credentialing service for healthcare providers and facilities.

The post claims the data originates from a December 2024 breach affecting 274,534 users. The compromised fields are listed as city, county, postal code, state, email addresses and names. The archive is shown as 4.6 MiB compressed and 18.6 MiB raw, with a SHA-256 hash provided for the file. Access to the hidden content requires 8 points. The dataset, its source, the claimed breach date, affected-user count and current availability have not been independently verified.

Post details

OrganizationMedCred
CountryIreland flagIreland
SectorHealthcare credentialing
Actor"replaceboundless"
Claimed affected users274,534
Claimed incident dateDecember 2024
File size4.6 MiB compressed / 18.6 MiB raw
Post date shown

What the post claims

  • 274,534 users affected
  • Incident dated to December 2024
  • Names included
  • Email addresses included
  • City fields included
  • County fields included
  • Postal-code fields included
  • State fields included
  • 4.6 MiB compressed archive
  • 18.6 MiB raw size
  • SHA-256 hash provided
  • Download hidden behind an 8-point unlock

The supplied screenshot provides summary details about the alleged archive but does not show underlying sample records. No personal data from the purported dataset is reproduced in this report.

Screenshots

The supplied capture shows the MedCred claim, the stated 274,534-user scope, compromised data categories, archive sizes, SHA-256 hash and an 8-point requirement to unlock the hidden content.

IOCs & contact identifiers

Identifiers directly visible in the listing. These support correlation and do not independently verify the dataset claim.

TypeIdentifierSource
Actor handlereplaceboundlessScreenshot 1
SHA-256EEFFEA039B343799233415D492C3E5114BFDFDF9A07718263E654EDEB08977DScreenshot 1

The SHA-256 value identifies the archive referenced in the claim. No Tox ID, Session ID, attacker-controlled domain or attacker-controlled IP address is visible in the supplied material. No organization domain is clearly shown in the screenshot. URLs to any data will always be blurred out, but are available for subscribers on the threat feed or ransomware feed.

Mapped techniques

Claimed identifies behavior explicitly described by the actor. Inferred identifies an analytical mapping supported by the supplied material. Neither label means the activity has been independently verified.

  • Collection T1213.006 Data from Information Repositories: Databases Inferred The listing describes a structured user dataset containing names, email addresses and geographic fields. The supplied material does not disclose how the data was obtained or independently establish unauthorized access to MedCred systems.

Potential impact

If authentic, the claimed exposure could reveal names, email addresses and geographic information for healthcare-sector users. Those details could support targeted phishing, impersonation and social-engineering campaigns, particularly where attackers can associate individuals with healthcare organizations or professional credentialing activity.

Status Unverified

Dark Web Informer has not independently verified the dataset's authenticity, source, December 2024 breach date, 274,534-user scope, archive contents or current availability. The supplied screenshot documents the listing and archive metadata, not independent confirmation of the underlying dataset.

Dark Web Informer

Latest