LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › MedSkin Solutions Dr. Suwelack AG Listed by The Gentlemen Ransomware Group

HIGH severityUnverified claimHow we verify

MedSkin Solutions Dr. Suwelack AG Listed by The Gentlemen Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·September 14, 2026
MedSkin Solutions Dr. Suwelack AG Listed by The Gentlemen Ransomware Group

Reported September 14, 2026.

HIGH
Severity
September 14, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

MedSkin Solutions Dr. Suwelack AG was listed by The Gentlemen Ransomware Group on September 14, 2026, with the group claiming to hold data belonging to an undisclosed number of individuals. Anyone connected to the company should check official channels for further information and consider protective steps if their details may have been involved.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

On September 14, 2026, the ransomware group known as The Gentlemen listed MedSkin Solutions Dr. Suwelack AG on its leak site. That listing is an unverified accusation from an extortion crew. MedSkin Solutions Dr. Suwelack AG has not publicly confirmed the claim as of writing. Public detail on timing, method, scale, and what—if anything—was taken remains limited.

For people who deal with the company as employees, partners, suppliers, or customers, a leak-site claim matters because it can signal pressure tactics and possible future publication of files. It does not by itself prove that systems were compromised or that personal or business data is circulating. The responsible approach is to treat the claim as a claim, watch for official statements, and take proportionate precautions if you have a relationship with the firm.

What is being claimed

According to the listing, The Gentlemen have named MedSkin Solutions Dr. Suwelack AG (associated in public profiles with medskin-suwelack.com and described as a German biotechnology company) as a victim. The group’s post is the source of the allegation; independent confirmation from the company, a regulator, or a neutral breach index is not part of the available record.

The number of people potentially affected is unknown. The types of data involved are not disclosed in a verified inventory. Material accompanying the listing appears to reference broad business areas—such as finance and accounting, quality management and validation, manufacturing and production operations, corporate controlling and financial planning, health and safety and environmental compliance, marketing assets, supply chain and vendor management, legal and intercompany contracts, IT infrastructure and data repositories, and human resources—but those labels are the attackers’ framing, not a confirmed catalogue of stolen files. How the group says it obtained access, whether a ransom demand was made, and whether any deadline or sample files were published are not established in the facts provided. Undisclosed details should be treated as unknown rather than assumed.

The group behind it: The Gentlemen

The Gentlemen is a ransomware and extortion-oriented threat actor known in public reporting for encrypting environments where they can, exfiltrating data, and threatening to publish material on a dedicated leak site if payment is not made. Like other groups in this category, they typically rely on initial access through common enterprise weak points, move laterally where possible, and use double-extortion pressure: disruption plus the threat of exposure.

Public coverage of The Gentlemen has generally described them as operating in a commercially styled ransomware model—victim naming, countdowns, and staged releases—rather than as a purely destructive actor. That pattern does not prove what happened in any single case. For this listing, only what the group claims about MedSkin Solutions Dr. Suwelack AG is on the table; nothing in the available facts states that their standard playbook was followed end-to-end against this company, or that files were actually removed and retained.

Leak-site listings are marketing and leverage. They can recycle older material, inflate scope, or name organisations prematurely. Readers should separate the well-documented existence of the group from the unproven content of any one post.

About MedSkin Solutions Dr. Suwelack AG

MedSkin Solutions Dr. Suwelack AG is a German biotechnology company, founded in 1997 and based in Billerbeck near Münster. Firms in this sector develop and supply specialised skin- and tissue-related products and related technologies, often serving medical, aesthetic, or clinical supply chains. They typically sit at the intersection of manufacturing, regulated quality systems, and commercial distribution.

A claimed incident involving such an organisation is consequential because biotech and medical-adjacent businesses routinely handle sensitive operational data, partner and supplier records, and sometimes information tied to regulated processes. Employees, contractors, and counterparties may have shared identity, contract, or financial details in the ordinary course of work. Even when a breach is only alleged, the sector’s reliance on trust, compliance documentation, and continuous supply makes reputational and operational uncertainty costly—without requiring any conclusion that a compromise actually occurred.

The information in question

Verified public detail does not establish which data, if any, left the company’s control. The facts state that exposed data types are not disclosed. References on the listing to finance, quality management, manufacturing, HR, legal, IT repositories, and similar domains should be read as the group’s claims about what it wants victims and readers to believe, not as an audited inventory.

If files from an organisation of this kind were taken, firms in biotechnology and regulated manufacturing typically hold combinations of employee and HR records, vendor and supply-chain data, contracts, financial and controlling information, quality and validation documentation, compliance materials, and internal IT assets. That is a sector norm, not evidence of what is in any attacker’s possession here. Exact contents, formats, recency, and whether personal data of private individuals is included remain unconfirmed.

The real-world impact

For individuals, the practical risk is conditional. If personal or employment-related data were involved, possible outcomes include targeted phishing that references real job titles or internal projects, fraud attempts using business context, or longer-term misuse of identity details. If only corporate operational files were at issue, employees might still see knock-on effects such as disrupted systems, changed login procedures, or social-engineering attempts impersonating IT or finance staff. None of these outcomes is established for this listing; they are the usual risk categories people weigh when a named employer or partner appears on a leak site.

For the organisation, an extortion listing can mean business interruption if systems were encrypted, legal and notification questions if personal data were later shown to be involved, and pressure on customer and supplier confidence. Because the company has not publicly confirmed the claim, external parties cannot yet map those risks to a known event timeline. A leak-site entry alone does not prove negligence, successful intrusion, or data publication; it establishes that a criminal group chose to name the firm.

Scale is unknown. Without confirmed counts of people or records, impact assessments should stay proportional: monitor official channels, avoid treating attacker marketing as a full breach report, and prepare for ordinary identity and invoice fraud patterns that rise whenever a company name trends in criminal forums.

If your data was involved

If you are an employee, former employee, supplier, or customer and you worry your information could be implicated, act on the possibility rather than on certainty. Prefer official notices from MedSkin Solutions Dr. Suwelack AG over screenshots from leak sites. Be sceptical of unexpected emails or calls that cite the incident and urge urgent payment, password entry, or transfer of funds. Where you use shared credentials with work accounts, change passwords on important personal accounts, enable multi-factor authentication, and watch bank and credit activity for unfamiliar activity. Keep copies of any genuine company communications for your records.

If HR or identity data might be in scope, consider freezes or alerts with credit agencies where that is available in your country, and treat tax or benefits-related messages with extra caution. Do not assume your data is “out” solely because of the listing; do take steps that reduce harm if it later is. Readers can also run a free exposure scan of their email to check whether their information has already surfaced in known breach data sets, which can help separate this claim from older, unrelated exposures.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

SourceLeak-site claim data adapted from RansomLook.io, used under CC BY 4.0.

CompanyMedSkin Solutions Dr. Suwelack AG security record
84/100
DoxxScan™ · Low doxx risk
B- 76Above-average record

1 reported incident on record.

See MedSkin Solutions Dr. Suwelack AG’s full breach history →

More recent breaches

Cedars Foods Listed by The Gentlemen Ransomware GroupSeptember 14, 2026TMI Tecnicas Mecanicas Ilerdenses Listed by The Gentlemen Ransomware GroupSeptember 14, 2026Aurora Technologies Listed by The Gentlemen Ransomware GroupSeptember 14, 2026Dome Gold Mines Listed by The Gentlemen Ransomware GroupSeptember 14, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the MedSkin Solutions Dr. Suwelack AG Listed by The Gentlemen Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by thegentlemen — unverified claim, pending independent verification. Leak-site claim data adapted from RansomLook.io, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram