MedCred Dataset Claim Lists 274,534 Users With Names, Email and Address Information
Overview
An actor using the handle "replaceboundless" claims to have uploaded a MedCred dataset for download. The listing describes MedCred as an Ireland-based credentialing service for healthcare providers and facilities.
The post claims the data originates from a December 2024 breach affecting 274,534 users. The compromised fields are listed as city, county, postal code, state, email addresses and names. The archive is shown as 4.6 MiB compressed and 18.6 MiB raw, with a SHA-256 hash provided for the file. Access to the hidden content requires 8 points. The dataset, its source, the claimed breach date, affected-user count and current availability have not been independently verified.
Post details
What the post claims
- 274,534 users affected
- Incident dated to December 2024
- Names included
- Email addresses included
- City fields included
- County fields included
- Postal-code fields included
- State fields included
- 4.6 MiB compressed archive
- 18.6 MiB raw size
- SHA-256 hash provided
- Download hidden behind an 8-point unlock
The supplied screenshot provides summary details about the alleged archive but does not show underlying sample records. No personal data from the purported dataset is reproduced in this report.
Screenshots
IOCs & contact identifiers
Identifiers directly visible in the listing. These support correlation and do not independently verify the dataset claim.
| Type | Identifier | Source |
|---|---|---|
| Actor handle | replaceboundless | Screenshot 1 |
| SHA-256 | EEFFEA039B343799233415D492C3E5114BFDFDF9A07718263E654EDEB08977D | Screenshot 1 |
The SHA-256 value identifies the archive referenced in the claim. No Tox ID, Session ID, attacker-controlled domain or attacker-controlled IP address is visible in the supplied material. No organization domain is clearly shown in the screenshot. URLs to any data will always be blurred out, but are available for subscribers on the threat feed or ransomware feed.
Mapped techniques
Claimed identifies behavior explicitly described by the actor. Inferred identifies an analytical mapping supported by the supplied material. Neither label means the activity has been independently verified.
- Collection T1213.006 Data from Information Repositories: Databases Inferred The listing describes a structured user dataset containing names, email addresses and geographic fields. The supplied material does not disclose how the data was obtained or independently establish unauthorized access to MedCred systems.
Potential impact
If authentic, the claimed exposure could reveal names, email addresses and geographic information for healthcare-sector users. Those details could support targeted phishing, impersonation and social-engineering campaigns, particularly where attackers can associate individuals with healthcare organizations or professional credentialing activity.
Status Unverified
Dark Web Informer has not independently verified the dataset's authenticity, source, December 2024 breach date, 274,534-user scope, archive contents or current availability. The supplied screenshot documents the listing and archive metadata, not independent confirmation of the underlying dataset.
