LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Scanbo Listed by killsec Ransomware Group

HIGH severityUnverified claimHow we verify

Scanbo Listed by killsec Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·September 22, 2025
Scanbo Listed by killsec Ransomware Group

Reported September 22, 2025.

HIGH
Severity
September 22, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Scanbo has been listed by the killsec ransomware group following the exfiltration of internal files in a ransomware attack. The incident was reported on September 22, 2025; anyone connected to Scanbo should verify whether their data was involved and review their accounts for suspicious activity.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

People connected to Scanbo face uncertainty after the company appeared on a ransomware group's leak site. Public reporting indicates that internal files may have been taken, yet the number of individuals affected remains unknown and the precise contents of any stolen material have not been confirmed. For anyone who has shared personal, medical, or professional information with the organisation, the practical stakes are clear: that data could be used for further fraud, identity misuse, or unwanted contact if it has left the company's control.

On 22 September 2025 Scanbo was listed by the group known as killsec. The listing itself is a claim by the attackers that they exfiltrated internal files during a ransomware attack; independent verification of the full scope has not been published. Until more detail emerges, those who interact with Scanbo have limited visibility into whether their own records are involved.

Inside the incident

According to the available public record, Scanbo was named on the killsec ransomware leak site on 22 September 2025. The group claims to have stolen internal data as part of a ransomware attack. No confirmed figure for the number of people affected has been released, and the exact method of intrusion, the duration of any access, and the total volume of material taken remain undisclosed. The only data category named in reporting is "internal files." Beyond the leak-site listing and the group's assertion of exfiltration, further technical or forensic particulars have not been made public.

Inside killsec

Killsec is a ransomware operation that has been active in recent years and is known for double-extortion tactics. Like many such groups, it typically encrypts systems while also copying data, then threatens to publish the material on a dedicated leak site if a ransom is not paid. The group has previously listed organisations across multiple sectors, using the public posting of victim names and sample files as pressure. Its communications are usually brief and claim-oriented; listings are therefore best treated as unverified assertions until corroborated by the victim organisation or independent investigators. In this case the group claims to have taken internal files from Scanbo; no additional statements specific to this incident beyond that claim appear in the public summary.

Who is Scanbo?

Scanbo operates in the health-technology sector, offering portable diagnostic tools and related software that support primary-care assessments. Organisations of this type commonly process patient identifiers, clinical measurements, contact details, and operational records belonging both to end users and to partner clinics or clinicians. A breach involving such an entity is consequential because the data it holds can be sensitive and long-lived; even limited internal files may contain enough personal or medical information to create ongoing risk for individuals. Public background on the company does not include any admission of fault or confirmed negligence in this incident; the only established fact is the listing itself.

What was likely exposed

The facts name only "internal files" as the material the group claims to have exfiltrated. No inventory of specific data fields—such as names, dates of birth, health readings, email addresses, or financial details—has been published. Organisations that provide diagnostic and health-related services typically store patient contact information, clinical results, device logs, and internal business documents. Whether any of those categories were present in the files allegedly taken from Scanbo remains unconfirmed. Readers should therefore treat the exposure as possible rather than proven for any particular data type.

The real-world impact

For individuals, the principal risks are secondary misuse of personal or health-related information: targeted phishing that references genuine details, attempts at identity fraud, or unwanted marketing based on medical context. Because the number of people affected is unknown, the scale of these risks cannot yet be quantified. For Scanbo the consequences include potential regulatory scrutiny, the cost of investigation and remediation, and the need to communicate with partners and users once more information becomes available. No dollar amounts, ransom demands, or confirmed operational disruptions have been reported in the public summary.

What to do if you're exposed

If you have an account, appointment history, or other relationship with Scanbo, monitor financial and medical statements for unexpected activity and treat unsolicited messages that reference the company with caution. Enable multi-factor authentication on related email and health-portal accounts where available, and consider placing a fraud alert with credit-reporting agencies if you believe sensitive identifiers may be involved. Because the exact contents of the claimed theft remain undisclosed, a practical next step is to check whether your email address has already appeared in other known breach data sets; free exposure-scan tools can perform that check quickly and without cost. Continue to follow any official notices Scanbo may issue as further details become public.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyScanbo security record
84/100
DoxxScan™ · Low doxx risk
B- 76Above-average record

1 reported incident on record.

See Scanbo’s full breach history →

More recent breaches

BEHCA Listed by killsec Ransomware GroupSeptember 22, 2025BFLI Listed by killsec Ransomware GroupSeptember 10, 2025Design Design Listed by killsec Ransomware GroupMarch 31, 2025grade results Listed by killsec Ransomware GroupDecember 24, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the Scanbo Listed by killsec Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by killsec — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram