The gemotest.ru Breach: 6.3 Million Patient Records Hit the Dark Web
In April 2022, a massive database belonging to the Russian medical laboratory chain gemotest.ru (Гемотест) was exfiltrated and apeared on underground forums, exposing the personal records of over 6.3 million patients. Unlike ransomware incidents that make headlines immediately, this breach circulated quietly for months before threat actors began actively leveraging the data for phishing campaigns and identity theft operations targeting Russian-speaking populations.
What Attackers Can Do With gemotest.ru Patient Data
With full names, birthdays, genders, email addresses, and phone numbers all in a single dataset, cybercriminals are partcularly well-positioned to craft highly convincing spear-phishing messages. Attackers can impersonate medical staff, insurance providers, or government agencies, using the victim's real personal details to build trust before requesting sensitive actions or payments. The medical context makes targets more likely to respond urgently.
What Was Exposed in the gemotest.ru (Гемотест) Breach
- Email Address
- First Name
- Last Name
- Birthday
- Gender
- Phone Number
Why This Medical Breach Carries Long-Term Risk
Medical and demographic data does not expire the way passwords do. A birthday, full name, and phone number recieved from this breach can be used years later to pass identity verification checks, open fraudulent accounts, or build synthetic identities. Victims may not realize they have been affected until damage has already occured across multiple services and financial institutions.
How a Database Breach Works
In a database breach, an attacker gains unauthorized access to a backend data store, typically by exploiting unpatched software vulnerabilities, misconfigured access controls, or stolen administrative credentials. Once inside, they can silently copy millions of records without triggering immediate alerts. The stolen data is then packaged and sold or posted on dark web forums, often surfacing weeks or months after the initial intrusion.
Check If Your Data Was Exposed
HEROIC's dark web monitoring database contains over 400 billion indexed records from thousands of breaches, including healthcare and medical data leaks like this one. Search now to find out whether your email address, phone number, or personal details appeared in the gemotest.ru breach or any other known data leak -- and take action before attackers do.
Breach Breakdown
6,340,122 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds