A threat actor operating under the handle Soral has posted a free leak claiming to contain 2,064,071 medical professional records allegedly sourced from H1 (h1.co), a U.S.-based healthcare data analytics company. The post surfaced on an underground forum on June 10, 2026, with sample records and field listings made public and the full dataset placed behind a reply gate. As tracked by Dark Web Informer, the claim remains unverified, and H1 has not publicly addressed it.
What Happened
On June 10, 2026, a forum user identified as Soral, flagged with elevated "GOD user" status, advertised a database said to be lifted from H1's medical-professional directory. The actor released sample records and a description of the exposed fields to substantiate the claim, while gating the complete download behind forum replies, a common tactic to drive engagement and reputation on underground boards.
The listing prices the data as a free leak rather than a paid sale, which typically widens distribution and lowers the barrier for opportunistic actors to obtain and weaponize the dataset. H1 operates in the healthcare technology and data analytics sector, aggregating information on medical professionals. Much of the data appears consistent with public professional registries, including France's RPPS identifier system, suggesting at least partial derivation from openly available sources.
The claim has not been independently confirmed, and the record count, authenticity, and true origin of the data all remain open questions at the time of reporting.
What Was Taken
The actor claims the dataset contains 2,064,071 professional records. According to the field listing posted to the forum, each record may include:
- Full names and civility (title)
- Sex and country
- Medical specialties
- Diploma and license names
- Years of experience
- Workplace names and sector
- Profile photos
Notably, the listed fields are entirely professional in nature. There is no indication that patient data, contact details such as email addresses or phone numbers, or account credentials are present. The per-record sensitivity is therefore lower than a typical patient or consumer breach. The risk here is driven by scale and aggregation rather than by individually secret information, since a portion of these attributes can be found in public registries.
Why It Matters
A consolidated, searchable directory of more than two million medical professionals, complete with names, specialties, qualifications, employers, and photographs, is a high-value targeting resource even when assembled from individually public fields. The aggregation is the threat: it removes the friction of collecting and correlating this information manually.
For attackers, this kind of dataset enables convincing, sector-specific phishing and impersonation campaigns against healthcare organizations. Photos and credential details make pretexting more believable, and workplace mapping lets adversaries craft targeted lures aimed at specific clinics, hospitals, or specialties. Because the leak is free, defenders should assume broad availability rather than limited circulation.
That said, defenders should calibrate response to the actual contents. Absent patient records, credentials, or contact data, this is primarily a social-engineering enabler, not a direct account-compromise event.
The Attack Technique
No intrusion method has been disclosed. The actor has not described how the data was obtained, and the possibility that it was scraped or compiled from public professional registries rather than extracted through a system compromise cannot be ruled out. The presence of RPPS-style registry data points toward at least partial aggregation of openly available records.
Until H1 confirms or denies a breach and any forensic detail emerges, the root cause, whether unauthorized database access, an exposed API, a misconfigured store, or registry scraping, remains unknown.
What Organizations Should Do
- Treat the dataset as publicly circulating and brief healthcare-facing staff on a likely uptick in targeted phishing and impersonation attempts.
- Reinforce verification procedures for inbound requests that reference professional credentials, specialties, or employer details, since attackers may use these to build trust.
- Strengthen email authentication and anti-impersonation controls (DMARC, DKIM, SPF) and tune filtering for healthcare-themed lures.
- If you are an H1 customer or partner, request clarification directly from the vendor and monitor for official guidance.
- Audit your own exposure of professional directories and APIs, applying rate limiting and access controls to reduce mass-scraping risk.
- Monitor underground forums and credential-exposure feeds for confirmation, expanded datasets, or follow-on listings tied to Soral.
Sources: H1 Data Breach: 2M+ Medical Professional Records Leaked