Globus Medical Data Breach Investigation

Data Breach Blog

Data Breach

Globus Medical Data Breach Investigation

Almeida Law Group Calendar Icon

Date of data breach:

September 1, 2026

by: Almeida Law Group

Attorneys at Almeida Law Group are investigating whether a class action lawsuit can be filed on behalf of individuals affected by a possible Globus Medical data breach. According to dark web monitoring sources, a hacker group calling itself Falcon claimed responsibility for a cyberattack on Globus Medical in a post first observed in August 2026, alleging it had gained access to internal company systems. As of this writing, Globus Medical has not issued a public confirmation of the incident, and the exact scope of any exposed data remains unknown. If you believe you were affected, contact Almeida Law Group.

About Globus Medical

Globus Medical, Inc. (NYSE: GMED) is a publicly traded medical device company headquartered in Audubon, Pennsylvania. Founded in 2003, the company develops and commercializes musculoskeletal solutions, including spinal implants, orthopedic trauma devices, joint reconstruction products, and robotic and navigation surgical systems. In September 2023, the company completed a $3.1 billion merger with NuVasive, creating one of the largest musculoskeletal device companies in the world. Globus Medical employs approximately 6,000 people and serves customers in more than 50 countries. Because the company operates in the medical device and healthcare technology space and maintains clinical registry data, regulatory submissions, and commercial contracts, the types of information potentially at issue in any incident may be sensitive — though the company’s own statement indicates no sensitive customer or patient data was exfiltrated.

What Happened?

On August 30th, 2026, Ransomware.live reported that the Falcon ransomware group listed Globus Medical on its dark web leak site. The group claimed to have exfiltrated 2.96 TB of data and alleged the stolen files include over 51,000 customer records from Microsoft Power BI, FDA feedback, 510(k) submissions, PMA approval letters, TGA suspension proposals, product complaint logs, serious adverse event narratives, CAPA investigation findings, merger diligence and integration documents, FTC antitrust review materials, financial statements, deal models, board meeting minutes, executed NDAs, distribution contracts, and patient demographics and history from clinical registries. These are attacker-side allegations and have not been independently verified.

Notably, Globus Medical itself acknowledged a cybersecurity incident six days earlier, on August 24th, 2026, through a statement posted on its investor relations page. The company stated that it had detected unauthorized access to a limited subset of employee corporate email accounts, files, and data; that it immediately activated incident response protocols and initiated containment measures; and that preliminary findings indicated no sensitive customer, consumer, or patient information was exfiltrated, that unauthorized access had been terminated, and that the company had no indication of ransomware or malware. The company’s disclosure directly contradicts the Falcon group’s claims regarding both ransomware deployment and the scope of any exfiltration.

Regarding the threat actor: Falcon is a newly emerged group first observed in August 2026, with only two claimed victims as of the time of this writing. Cybersecurity firm GuidePoint Security has linked the Falcon brand to a broader threat cluster designated UNC6671 by Google Threat Intelligence Group and CORDIAL SPIDER by Okta Threat Intelligence, which uses adversary-in-the-middle phishing and vishing techniques and operates under multiple extortion brands, including Falcon, Helix, Pink, and Redact. WatchGuard characterizes Falcon as a “data broker” type rather than a traditional ransomware operator. Ransomware.live itself notes that claims from this emerging group should be treated with caution. No independent corroborating source has verified the Falcon group’s specific allegations against Globus Medical.

Key Facts at a Glance

What Should You Do?

Even where a company reports that sensitive customer or patient data was not exfiltrated, anyone who interacted with Globus Medical — including patients who participated in clinical registries, commercial partners, or employees — should remain alert to signs of fraud and unauthorized activity. You can place a free fraud alert or credit freeze with the three major credit bureaus (Equifax, Experian, and TransUnion) to help prevent new accounts from being opened in your name. Monitor your financial accounts and obtain a free copy of your credit report at AnnualCreditReport.com. If you believe your personal information has been misused, report it at IdentityTheft.gov. Because the Falcon group’s claims reference patient demographics and clinical registry data, patients should also review their Explanation of Benefits statements and request copies of their medical records to check for any unfamiliar entries.

Your Legal Rights

If your personal or health information was involved in this breach, you may have legal rights depending on the facts of the incident and the law in your state. Almeida Law Group represents consumers in data breach and privacy litigation and can help you evaluate whether you may have a claim. Contact us at (708) 529-5418 or through our contact page for a free case evaluation.

Were You a Victim of a Data Breach?

"*" indicates required fields

By clicking the SEND button and submitting this form, I consent to receive communications from Almeida Law Group LLC and their co-counsel by phone call, email, and/or SMS regarding this matter and other potential legal matters. I understand that message and data rates may apply and that consent to such contact is not required for use of these services. Message frequency varies. Reply STOP to opt-out and HELP for help. I also agree to the Privacy Policy. I understand that my information may be shared with advertising partners to deliver targeted advertisements and optimize outreach efforts. I confirm that I am at least 18 years old. I have read and understand the disclaimer above. I agree my use of this site and the information provided here is not intended to create and does not create an attorney client relationship with the Almeida Law Group and/or attorneys employed by the Firm. No attorney client relationship is intended or created unless and until an engagement agreement is signed by all relevant parties. The contents of this site constitute attorney advertising and not legal advice; therefore you should not act or rely upon any information contained herein, and should always seek the advice of an attorney.

Resourceful. Resilient. Relentless.

Contact us today to get the justice you and your family deserve.