A French hospital suffered a major data breach that exposed the medical records of 750,000 patients. Attackers gained access to the electronic patient records system.

The breach became known when an attacker, using the alias “nears” (formerly near2tlg), claimed to have attacked multiple healthcare in France. He claimed to have accessed the records of more than 1,500,000 people.
The hacker says he breached the MediBoard from Software Medical Group, a company that offers Electronic Patient Record (EPR) solutions across Europe.
See also: Georgia hospital hackers threaten to leak data
Softway Medical Group confirmed that there was a breach of a MediBoard account, which likely resulted from stolen credentials used by the hospital.
Softway Medical Group states that the exposed data was not directly managed by them, but was hosted by the hospital.
“On November 19, 2024, a cyberattack was detected on a healthcare, via Mediboard software.“.
“We would like to emphasize that the affected health data was not hosted by Softway Medical Group“.
BleepingComputer reached out to Softway Medical Group for clarification on which account and at what level was compromised. A spokesperson reportedly said: “We can confirm that our software was not responsible. Rather, a privileged account in the customer’s infrastructure was compromised by an individual who exploited the standard functionality of the software.”
After the breach, the attacker began selling access to the MediBoard platform for several French hospitals, including Centre Luxembourg, Clinique Alleray-Labrouste, Clinique Jean d'Arc, Clinique Saint-Isabelle, and Hôpital Privé de Thiais.
This access allegedly allowed the buyer to view sensitive health and billing information the hospitals', patient records, and the ability to schedule and modify appointments or medical records.
To prove that he had gained access to the MediBoard accounts, the hacker also put up for sale the records of 758,912 patients from an unnamed French hospital.
See also: Ransomware attack hits Bainbridge Hospital
The data breach appears to affect the following hospital patient information:
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
- Full name
- Date of birth
- Genus
- Home address
- Email address
- Phone number
- Doctor
- Recipes
- Health card history
No buyers have been announced at this time. However, even if they don't sell, there is always the risk that they could be leaked online.

Hospitals: More effective strategies for protecting against cyberattacks
One of the most effective protection strategies is training staff. Staff who are informed about the techniques used by attackers can recognize and, to some extent, avoid cyberattacks.
Implementing up-to-date security protocols is another important strategy. This includes regularly updating software and systems, installing the latest security patches , and implementing procedures that protect data.
Using advanced security tools, such as systems prevention intrusion and cyberattack detection and prevention tools, can help address threats before they cause damage.
See also: McLaren Hospitals Outage Linked to INC Ransomware Attack
Additionally, hospitals must implement access policies to control who has access to patient data. This may include the use of credentials, such as usernames and passwords ,as well as implementing policies that require staff to change their passwords regularly.
They can also use external security services to monitor their networks for potential attacks. These services can include monitoring network traffic, detecting “anomalies” and responding to potential threats.
Finally, creating a breach response plan can be crucial. This plan should include threat analysis , attack identification, isolation of the compromised system, and restoration of systems to a secure state.
Source: www.bleepingcomputer.com
