SYS::ONLINE
Wasteland.
Briefs1674
Issues21
SinceFeb 2026
LIVE
▣ Breach H1-CO-DATA 2026-06-10

H1: Soral Leaks 2M+ Medical Professional Records

"A threat actor operating under the handle Soral has posted a free leak claiming to contain 2,064,071 medical professional records allegedly sourced from H1 (h1.co), a U.S.-based healthcare data analytics company. The…"

A threat actor operating under the handle Soral has posted a free leak claiming to contain 2,064,071 medical professional records allegedly sourced from H1 (h1.co), a U.S.-based healthcare data analytics company. The post surfaced on an underground forum on June 10, 2026, with sample records and field listings made public and the full dataset placed behind a reply gate. As tracked by Dark Web Informer, the claim remains unverified, and H1 has not publicly addressed it.

What Happened

On June 10, 2026, a forum user identified as Soral, flagged with elevated "GOD user" status, advertised a database said to be lifted from H1's medical-professional directory. The actor released sample records and a description of the exposed fields to substantiate the claim, while gating the complete download behind forum replies, a common tactic to drive engagement and reputation on underground boards.

The listing prices the data as a free leak rather than a paid sale, which typically widens distribution and lowers the barrier for opportunistic actors to obtain and weaponize the dataset. H1 operates in the healthcare technology and data analytics sector, aggregating information on medical professionals. Much of the data appears consistent with public professional registries, including France's RPPS identifier system, suggesting at least partial derivation from openly available sources.

The claim has not been independently confirmed, and the record count, authenticity, and true origin of the data all remain open questions at the time of reporting.

What Was Taken

The actor claims the dataset contains 2,064,071 professional records. According to the field listing posted to the forum, each record may include:

Notably, the listed fields are entirely professional in nature. There is no indication that patient data, contact details such as email addresses or phone numbers, or account credentials are present. The per-record sensitivity is therefore lower than a typical patient or consumer breach. The risk here is driven by scale and aggregation rather than by individually secret information, since a portion of these attributes can be found in public registries.

Why It Matters

A consolidated, searchable directory of more than two million medical professionals, complete with names, specialties, qualifications, employers, and photographs, is a high-value targeting resource even when assembled from individually public fields. The aggregation is the threat: it removes the friction of collecting and correlating this information manually.

For attackers, this kind of dataset enables convincing, sector-specific phishing and impersonation campaigns against healthcare organizations. Photos and credential details make pretexting more believable, and workplace mapping lets adversaries craft targeted lures aimed at specific clinics, hospitals, or specialties. Because the leak is free, defenders should assume broad availability rather than limited circulation.

That said, defenders should calibrate response to the actual contents. Absent patient records, credentials, or contact data, this is primarily a social-engineering enabler, not a direct account-compromise event.

The Attack Technique

No intrusion method has been disclosed. The actor has not described how the data was obtained, and the possibility that it was scraped or compiled from public professional registries rather than extracted through a system compromise cannot be ruled out. The presence of RPPS-style registry data points toward at least partial aggregation of openly available records.

Until H1 confirms or denies a breach and any forensic detail emerges, the root cause, whether unauthorized database access, an exposed API, a misconfigured store, or registry scraping, remains unknown.

What Organizations Should Do

Sources: H1 Data Breach: 2M+ Medical Professional Records Leaked