Attorneys at Almeida Law Group are investigating whether a class action lawsuit can be filed on behalf of individuals affected by a possible Globus Medical data breach. According to dark web monitoring sources, a hacker group calling itself Falcon claimed responsibility for a cyberattack on Globus Medical in a post first observed in August 2026, alleging it had gained access to internal company systems. As of this writing, Globus Medical has not issued a public confirmation of the incident, and the exact scope of any exposed data remains unknown. If you believe you were affected, contact Almeida Law Group.
About Globus Medical
Globus Medical, Inc. (NYSE: GMED) is a publicly traded medical device company headquartered in Audubon, Pennsylvania. Founded in 2003, the company develops and commercializes musculoskeletal solutions, including spinal implants, orthopedic trauma devices, joint reconstruction products, and robotic and navigation surgical systems. In September 2023, the company completed a $3.1 billion merger with NuVasive, creating one of the largest musculoskeletal device companies in the world. Globus Medical employs approximately 6,000 people and serves customers in more than 50 countries. Because the company operates in the medical device and healthcare technology space and maintains clinical registry data, regulatory submissions, and commercial contracts, the types of information potentially at issue in any incident may be sensitive — though the company’s own statement indicates no sensitive customer or patient data was exfiltrated.
What Happened?
On August 30th, 2026, Ransomware.live reported that the Falcon ransomware group listed Globus Medical on its dark web leak site. The group claimed to have exfiltrated 2.96 TB of data and alleged the stolen files include over 51,000 customer records from Microsoft Power BI, FDA feedback, 510(k) submissions, PMA approval letters, TGA suspension proposals, product complaint logs, serious adverse event narratives, CAPA investigation findings, merger diligence and integration documents, FTC antitrust review materials, financial statements, deal models, board meeting minutes, executed NDAs, distribution contracts, and patient demographics and history from clinical registries. These are attacker-side allegations and have not been independently verified.
Notably, Globus Medical itself acknowledged a cybersecurity incident six days earlier, on August 24th, 2026, through a statement posted on its investor relations page. The company stated that it had detected unauthorized access to a limited subset of employee corporate email accounts, files, and data; that it immediately activated incident response protocols and initiated containment measures; and that preliminary findings indicated no sensitive customer, consumer, or patient information was exfiltrated, that unauthorized access had been terminated, and that the company had no indication of ransomware or malware. The company’s disclosure directly contradicts the Falcon group’s claims regarding both ransomware deployment and the scope of any exfiltration.
Regarding the threat actor: Falcon is a newly emerged group first observed in August 2026, with only two claimed victims as of the time of this writing. Cybersecurity firm GuidePoint Security has linked the Falcon brand to a broader threat cluster designated UNC6671 by Google Threat Intelligence Group and CORDIAL SPIDER by Okta Threat Intelligence, which uses adversary-in-the-middle phishing and vishing techniques and operates under multiple extortion brands, including Falcon, Helix, Pink, and Redact. WatchGuard characterizes Falcon as a “data broker” type rather than a traditional ransomware operator. Ransomware.live itself notes that claims from this emerging group should be treated with caution. No independent corroborating source has verified the Falcon group’s specific allegations against Globus Medical.
Key Facts at a Glance
- Company or Organization: Globus Medical, Inc. (NYSE: GMED)
- Industry: Medical Devices / Healthcare Technology
- Location: Audubon, Pennsylvania, United States
- Incident type: Ransomware leak-site allegation (Falcon group); company separately confirmed unauthorized access to employee email accounts and data
- Prior breach: No prior publicly reported data breaches found for Globus Medical
- Source: Ransomware.live – Globus Medical (Falcon claim); Globus Medical Investor Relations – Cybersecurity Statement; GuidePoint Security – Falcon Extortion Operations; GalaxyWarden – Globus Medical Falcon Listing
What Should You Do?
Even where a company reports that sensitive customer or patient data was not exfiltrated, anyone who interacted with Globus Medical — including patients who participated in clinical registries, commercial partners, or employees — should remain alert to signs of fraud and unauthorized activity. You can place a free fraud alert or credit freeze with the three major credit bureaus (Equifax, Experian, and TransUnion) to help prevent new accounts from being opened in your name. Monitor your financial accounts and obtain a free copy of your credit report at AnnualCreditReport.com. If you believe your personal information has been misused, report it at IdentityTheft.gov. Because the Falcon group’s claims reference patient demographics and clinical registry data, patients should also review their Explanation of Benefits statements and request copies of their medical records to check for any unfamiliar entries.
Your Legal Rights
If your personal or health information was involved in this breach, you may have legal rights depending on the facts of the incident and the law in your state. Almeida Law Group represents consumers in data breach and privacy litigation and can help you evaluate whether you may have a claim. Contact us at (708) 529-5418 or through our contact page for a free case evaluation.