In short: In July 2026, more than 88 million Russian medical records were exposed in a single month — more than all previous months of the year combined. The data surfaced in specialised Telegram channels and on darknet forums, where it is already being exploited for fraud and targeted attacks. Here is what happened and how to reduce the risk to your personal data.
What happened: the numbers and their context
According to Perspektivny Monitoring (a subsidiary of InfoTeCS Group), which conducts monthly breach tracking in Russia, July 2026 produced 17 publicly documented incidents. Combined, these exposed more than 100 million records — a single-month record. Of those, 88.37 million came from the healthcare sector alone.
For context: in June 2026, healthcare leaks amounted to 1.7 million records, and March through May combined produced 2.2 million. July's spike was driven by two large incidents, one of which involved a major medical information system. The organisations have not been officially named, but the data is already circulating on specialised underground platforms.
Nikolai Galkin, Head of Cyber Threat Research at Perspektivny Monitoring, stated that medical data has been “leaking regularly for four consecutive months,” pointing to “extremely weak data security across the healthcare sector.” The incidents were covered by CNews and Anti-Malware.ru.
Why medical records are especially dangerous in the wrong hands
Medical records rank among the most valuable assets on stolen-data markets. Unlike a bank card that can be cancelled in minutes, diagnoses, treatment histories, insurance details, and prescription records remain actionable for years. A complete patient profile commands prices several times higher than a standard credential set on underground markets.
Concrete risks for individuals:
- Targeted fraud. Knowing a person's diagnosis, an attacker can construct a convincing phishing scenario — a call from “the clinic,” “the insurance company,” or a “subsidised medication delivery service.”
- Extortion and discrimination. Psychiatric, oncological, and reproductive diagnoses may be used to pressure individuals or their employers.
- Medical identity theft. Using someone's healthcare profile to claim benefits, purchase insurance policies, or apply for credit in their name.
- Building attack profiles. Medical data enriches the aggregated picture of a victim that breach compilers sell for automated account takeover campaigns.
How the data ends up in public
According to analysis by Anti-Malware.ru, stolen databases are published in specialised Telegram channels and on darknet marketplaces. Monetisation is rapid: data is purchased both in bulk for robocalling and spam campaigns, and selectively for targeted attacks on specific individuals.
The attack vectors that compromise healthcare systems are familiar: SQL injection through outdated software, weak administrator credentials, unprotected telemedicine APIs, and AI-assisted employee phishing — standard attacker tooling in 2026. An industry that has historically invested in clinical equipment rather than information security is now paying the price.
For a broader look at modern threat methods, see our coverage in the LiMP VPN blog.
What this means for your data right now
You can check whether your email address appears in known breach datasets at no cost and without registration using HaveIBeenPwned. If your address is listed, change passwords on every linked service immediately.
Steps worth taking regardless of the check result:
- Review data-sharing consents in your clinic and insurance portal accounts — revoke any you no longer need.
- Enable two-factor authentication on clinic patient portals, insurance dashboards, and medical aggregator accounts.
- Use a dedicated email address and phone number for healthcare services — this limits the blast radius of any single breach.
- Be sceptical of inbound calls from “clinics.” Always call back using the official number on the organisation's website, not a number provided by the caller.
- Encrypt your traffic on public networks. Open Wi-Fi in hospitals, clinics, and pharmacies is an additional interception vector. A VPN encrypts everything your device transmits and hides your requests from eavesdroppers — see how on our LiMP VPN features page.
Plans with a verified no-logs policy from 69 ₽/month: LiMP VPN pricing.
