A ransomware operation calling itself Falcon has listed Globus Medical, Inc. (NYSE: GMED) on its extortion site, claiming to have extracted roughly 2.96 TB of data including the company's entire Microsoft Power BI environment, FDA regulatory submissions, adverse event narratives, and merger diligence material. Ransomware.live logged the listing at 2026-08-30 14:29 UTC with an estimated attack date of 2026-08-30. Every figure in circulation traces back to Falcon's own post: as of publication there is no victim statement, no regulatory filing, and no vendor or CERT advisory corroborating the claim. Ransomware.live itself flags Falcon as an emerging group and advises that the claim "should be treated with caution until independently verified." Readers should treat this brief as coverage of an unverified extortion claim, not a confirmed breach.
What Happened
The primary artifact is the leak site entry catalogued by Ransomware.live, which reproduces Falcon's description of the haul and tags the victim as a healthcare-sector target in the medical devices category. Two write-ups from Undercode News, published the evening of 2026-08-30 and again on 2026-08-31, restate the same claim, with the second attributing its details to "Cybersecurity News Everyday and the associated ransomware monitoring report." Both Undercode pieces are downstream of the leak site listing rather than independent confirmation, and both hedge consistently, using "reportedly" and "allegedly" throughout.
On volume, the sources do not meaningfully conflict. The leak site and both Undercode articles all state 2.96 TB; the "nearly 3 TB" framing in one Undercode headline is a rounding of the same number, not a second estimate. The record count appears only once, in Falcon's own text: "over 51,000 records of your customers and more." No source offers a competing figure, which means there is no range to report here, only a single unverified assertion from the threat actor.
What is absent is as notable as what is present. None of the eight sources reviewed contains a Globus Medical statement on the incident, an 8-K, a state attorney general notification, or any HIPAA breach portal entry. There is also no indication in any source of encryption, system outage, or disruption to manufacturing or clinical support operations. The claim as it stands is exfiltration-and-extortion only.
What Was Taken
Falcon's inventory, as published on the leak site, is unusually specific for an emerging group and reads as a deliberate demonstration of regulatory leverage rather than a generic file dump. The claimed contents fall into four buckets.
Regulatory and product safety material: FDA feedback, 510(k) submissions, PMA approval letters, TGA suspension proposals, product complaint logs, serious adverse event narratives, and final CAPA investigation findings. The inclusion of Australian TGA suspension proposals alongside US FDA correspondence suggests the actor is claiming multi-jurisdictional regulatory files, not just domestic ones.
Corporate and transactional material: merger diligence decks, integration plans, FTC antitrust review documents, combined P&L statements, deal models, budget spreadsheets, board of directors meeting minutes and agendas, and executed NDAs.
Commercial relationships: distribution contracts naming partners and medical institutions.
Patient-adjacent data: patient demographics and history from clinical registries. This is the single most consequential item in the list and the least corroborated. Neither Undercode piece independently establishes it, and no notification obligation has been reported by any source, so it should be read strictly as a threat actor claim until Globus Medical or a regulator addresses it.
The corporate bucket carries obvious timing significance. Globus Medical announced its acquisition of Higgs Boson Health on 2026-08-26, four days before the leak site listing, and the company disclosed a bargain purchase gain of $110.5 million tied to its earlier Nevro acquisition in its Q2 2026 results. A claimed cache of diligence decks, integration plans, and FTC antitrust review documents intersects directly with live and recent transactions, which raises the coercive value of the data well above that of a static document archive.
Why It Matters
Globus Medical is not a marginal target. The company reported worldwide net sales of $789.6 million in Q2 2026, up 5.9% year over year, with GAAP net income of $151.6 million, and it reaffirmed full-year revenue guidance. A company at that scale with an active acquisition pipeline is exactly the profile that data-theft extortion crews price highest, because the material they claim to hold is time-sensitive to a transaction rather than merely embarrassing.
The regulatory dimension is what separates this from a routine corporate data theft claim. Pre-submission FDA correspondence, PMA approval letters, CAPA closure findings, and adverse event narratives are the documentary spine of a device maker's market authorization. Leaked in bulk, that material hands competitors a design and clearance roadmap, gives plaintiffs' counsel a discovery shortcut, and gives regulators in multiple jurisdictions a reason to ask questions the company would otherwise answer on its own schedule. The claimed TGA suspension proposals in particular imply exposure to an ongoing regulatory process abroad.
There is also a second-order supply chain concern. Distribution contracts naming partners and medical institutions, if genuinely in the set, convert one vendor compromise into a targeting list for downstream hospital systems, complete with named counterparties and commercial terms useful for business email compromise.
For defenders, the Power BI angle deserves specific attention. Falcon claims the entire Power BI tenant, not a file server. Business intelligence platforms are aggregation points by design: they pull from ERP, CRM, quality management, and clinical registry systems and join them into a single queryable layer. A single credential with broad workspace access can yield more consolidated sensitive data than weeks of lateral movement across source systems, and BI exports frequently sit outside the DLP and classification coverage applied to the underlying databases.
The Attack Technique
No source establishes an initial access vector for this incident. Neither Undercode article names a technique, and the leak site entry describes only the alleged outcome.
Two circumstantial threads are worth logging, with their limits stated plainly.
First, HudsonRock telemetry displayed alongside the Ransomware.live listing reports infostealer exposure associated with the victim domain: 12 compromised employees, 2 compromised users, 14 third-party employee credentials, and an external attack surface score of 10. This is generic exposure data attached to the victim profile by an automated integration. It is not evidence that any of those credentials were used in this intrusion, and it should not be reported as the entry point.
Second, and more suggestively, a group tracked as "Falcon" appears in a separate and better-documented campaign. Archyde and Mezha, both reporting on Apollo Global Management's confirmed cloud breach of July 6 to July 10, 2026, cite Google researchers describing an extortion campaign against private equity and financial firms run by clusters named Falcon, Helix, Pink, and Redact. In that campaign the operators impersonate IT helpdesk staff by phone, steering employees to spoofed login portals to surrender passwords and MFA tokens. Mezha, citing TechCrunch, and Archyde both attribute the naming to Google; Archyde adds that some intrusions in that campaign involved ransoms reaching up to $750,000, though that outlet renders currency and figures inconsistently elsewhere in the same piece, so treat the amount as approximate.
Whether the Falcon named by Google is the same Falcon now listing Globus Medical is not established by any source reviewed. The name is common, Ransomware.live classifies this Falcon as a new group, and no researcher has publicly linked the two. Analysts should hold this as a hypothesis to test, not a finding. That said, the hypothesis is operationally cheap to act on: helpdesk impersonation against an SSO tenant followed by mass export from a cloud BI platform is a coherent path to the outcome Falcon claims, and it is a path worth auditing regardless of who is behind this listing.
Globus Medical does maintain in-house incident response capability. Public LinkedIn profile data shows a Lead Information Security Engineer at the company, CISSP-certified, whose stated remit covers end-to-end incident response, SIEM and EDR monitoring, and SOAR playbook development. That says nothing about this incident's handling, but it does indicate the organization is not without a response function.
What Organizations Should Do
Audit business intelligence tenants as crown jewel systems. Inventory every Power BI, Tableau, or equivalent workspace, identify which datasets join regulatory, commercial, and patient-derived sources, and apply the same access review, classification, and DLP coverage you apply to the underlying databases. Restrict and alert on bulk export and dataset download operations.
Harden the helpdesk against voice-based social engineering. Given the Falcon-adjacent campaign documented against Apollo and warned about for Blackstone, Bridgewater, and Bain Capital, require out-of-band identity verification before any password or MFA reset, forbid agents from initiating resets on inbound calls alone, and rehearse the scenario with the service desk. Move high-value accounts to phishing-resistant FIDO2 authenticators so a relayed token is worthless.
Instrument cloud egress volumetrics. A claimed 2.96 TB extraction is not a subtle event. Establish per-user and per-application baselines for outbound data from SaaS and cloud tenants, and alert on multi-hundred-gigabyte deviations rather than relying solely on endpoint controls that never see the traffic.
Ingest infostealer credential feeds continuously. Corporate and third-party credentials for sale, of the kind HudsonRock reports against this domain, are a recurring precursor to extortion intrusions. Force resets and session revocation on any hit, and extend the check to contractor and distributor accounts holding tenant access.
Treat M&A windows as elevated risk periods. Diligence decks, integration plans, and antitrust review files concentrate leverage. Segment deal workspaces, apply time-bounded access, watermark distributed material, and pull access immediately at close.
Extend third-party questions to device suppliers. Hospital and health system security teams should ask device vendors whether distribution contracts, registry extracts, or institution-identifying data are held in cloud BI platforms, and what monitoring covers them.
Pre-plan the regulatory notification path. Device makers should have counsel-reviewed playbooks ready for FDA, TGA, and equivalent bodies, plus state and HIPAA notification triggers, so a leak site listing does not become the first version of the story regulators or customers hear.
Wasteland will update this brief if Globus Medical, a regulator, or an independent researcher addresses the claim. Until then, the 2.96 TB figure, the 51,000 record count, and the contents inventory remain assertions by the threat actor and nothing more.
Sources: Falcon Ransomware Strikes Globus Medical: Nearly 3 TB of Sensitive... | Victim: Globus Medical | Globus Medical Faces a Ransomware Crisis as Sensitive Healthcare Da... | Apollo Global Management Confirms Cloud Data Breach Following Socia... | Christopher Zukowski | Apollo Global Management Confirms Personal Data Breach Following Cl... | Globus Medical Announces Acquisition of Higgs Boson Health | Globus Medical Announces Financial Results for Q2 2026 - GMED