Omnicuris Data Breach (2025): What Was Exposed & What To Do
SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.
Omnicuris disclosed a data breach on 8 June 2025 affecting 215,000 individuals, with exposed records including names, email addresses, phone numbers, and geographic locations. If you have an account or prior contact with Omnicuris, review the company’s notices and consider changing passwords or enabling additional account protections.
In June 2025, Omnicuris, an Indian continuing medical education platform, experienced a data breach that exposed records belonging to approximately 200,000 healthcare professionals. Public reporting dated 8 June 2025 places the number of people affected at around 215,000. The exposed information included names, email addresses, phone numbers, geographic locations and additional attributes tied to professional expertise and training progress. Omnicuris has confirmed it is aware of the incident.
Details beyond these core facts remain limited. No public disclosure has clarified the precise method of intrusion, the exact duration of unauthorised access, or whether the data has been further circulated. For the healthcare professionals whose records were involved, the exposure of contact and professional details carries practical consequences that warrant careful attention.
Inside the incident
According to available reporting, the breach at Omnicuris came to light in June 2025 and involved roughly 200,000 records of healthcare professionals registered on the platform. The figure of people affected is given as 215,000 in some accounts. Confirmed data elements include names, email addresses, phone numbers and geographic locations, together with other attributes describing professional expertise and training progress.
Omnicuris has stated that it is aware of the incident. Public sources have not released further technical particulars such as the attack vector, the systems compromised, the timeline of detection, or any forensic findings. No independent verification of the full scope has been published, and no threat actor has been publicly attributed. The information currently available rests on the organisation’s acknowledgment and contemporaneous reporting of the approximate scale and the categories of data involved.
How a breach like this happens
Incidents of this type commonly begin with unauthorised access to systems that store user or professional profiles. Attackers may exploit unpatched software vulnerabilities, weak or reused credentials, misconfigured cloud storage, or phishing campaigns that target staff with privileged access. Once inside, they can extract databases containing contact details and professional records.
In many cases the stolen data is later offered for sale or posted on criminal forums. Organisations that hold large directories of professionals often become targets because the combination of verified identity information and contact details has value for further social-engineering or fraud attempts. The precise pathway used against Omnicuris has not been disclosed, so the above description remains general background rather than a reconstruction of this specific event.
Who is Omnicuris?
Omnicuris operates as a continuing medical education (CME) platform serving healthcare professionals in India. Such platforms typically provide online courses, certification tracking, webinars and progress records that allow doctors, nurses and other clinicians to meet ongoing professional-development requirements. Users create accounts that store personal contact information alongside details of their specialties, completed modules and training status.
Because the service sits at the intersection of professional identity and regulated medical education, the data it holds is more sensitive than a simple mailing list. A breach therefore affects not only personal privacy but also the integrity of professional records that may be referenced by employers, regulators or colleagues. The organisation’s role in the Indian healthcare-education sector makes the exposure of its user base consequential for the individuals concerned and for trust in digital CME services more broadly.
The information in question
Reporting states that the exposed records contained names, email addresses, phone numbers, geographic locations and other data attributes relating to professional expertise and training progress. These categories match the types of information a CME platform would ordinarily collect to deliver courses, issue certificates and communicate with users.
Exact field-level contents beyond the named categories have not been independently itemised in public sources. Organisations of this kind typically also retain login credentials, course-completion timestamps, specialty designations and sometimes institutional affiliations. Whether any of those additional fields were present in the leaked set remains unconfirmed. Readers should therefore treat only the explicitly listed data types as established and regard further details as presently undisclosed.
Why it matters
For the healthcare professionals whose records appear in the breach, the combination of name, email, phone number and location creates a ready-made profile that can be used for targeted phishing, voice scams or identity-based fraud. Attackers may impersonate medical boards, employers or colleagues, leveraging the professional context to increase credibility. Geographic data can further refine such attempts by suggesting local institutions or events.
For Omnicuris itself, the incident raises questions of operational security and the duty of care owed to a professional user base. Even when an organisation responds promptly once it becomes aware of a breach, the practical harm to individuals can persist for years if the data is reused in subsequent campaigns. The absence of public technical detail also leaves affected people without clear guidance on the full extent of exposure, which can prolong uncertainty.
If your data was in this breach
If you have used Omnicuris or believe your professional details may have been among the exposed records, begin by changing any passwords associated with the platform and with email accounts that share the same credentials. Enable multi-factor authentication wherever it is offered. Monitor email and phone communications for unexpected messages that reference medical education, certifications or professional opportunities, and treat unsolicited requests for further personal information with caution.
Consider placing fraud alerts with relevant credit or identity-protection services if you are concerned about broader misuse. You can also run a free exposure scan of your email address to check whether it has appeared in known breach data sets; such checks provide an additional, independent signal of whether your contact details have circulated. Remain alert for follow-up communications from Omnicuris itself regarding any official remediation steps or further notifications.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Pass'Sport Data Breach (2025)APOIA.se Data Breach (2025)SoundCloud Data Breach (2025)Under Armour Data Breach (2025)Latest breaches
Read GalaxyWarden’s full analysis of the Omnicuris Data Breach (2025) →
Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.