1,381 Total Swiss Customer Records Hit Dark Web in December 2024 Healthcare Breach
HEROIC analysts identified a data breach at Total Swiss, a biochemical healthcare company headquartered in Taipei City, Taiwan, with the compromised data surfacing on December 22, 2024. The exposed dataset contained 1,381 user records, along with numerous usermeta documents that may carry additional contextual information about accounts and device configurations. What drew immediate attention was the healthcare context: users of a health-focused company have a reasonable expectation that their personal contact details and system information will be handled with care, making any exposure a significant breach of trust alongside a security risk.
Why the Total Swiss Breach Is Dangerous
Healthcare and wellness brands attract users who share sensitive personal information and often have purchasing histories tied to health conditions or wellness goals. Even without medical records in this specific dataset, the combination of email addresses, phone numbers, and IP addresses enables targeted phishing and social engineering attacks that exploit the victim's known relationship with a health brand. IP addresses can also reveal home or work network locations, which carries implications for physical security and targeted network-based attacks.
What Was Exposed in the Total Swiss Breach
- Email addresses
- Phone numbers
- IP addresses
- Usermeta documents (may contain additional user and device information)
Why This Matters: Phishing, Fraud, and Identity Exposure
Email addresses and phone numbers together give attackers two direct channels to reach victims with fraudulent communications. Phishing messages referencing the victim's Total Swiss account will appear highly credible. Phone numbers enable SMS phishing (smishing) and voice-based scams (vishing) that can trick recipients into revealing additional personal or financial information. IP address exposure adds risk for network reconnaissance, where attackers map out vulnerable systems connected to the same network. The absence of password data does not make this breach low risk, since the contact details exposed are sufficient to launch effective identity theft campaigns.
How Healthcare Database Breaches Happen
Healthcare and wellness companies frequently handle customer data across web platforms, mobile apps, and backend databases that may not receive the same security investment as their core product operations. Attackers target these systems using SQL injection, brute-force attacks on administrative portals, or exploits against misconfigured cloud storage. Database exfiltration does not require sophisticated techniques when basic security controls are missing. Once extracted, the data is posted to dark web forums and marketplaces, where it can be purchased and used by multiple threat actors with different objectives.
Check If Your Data Was Exposed
HEROIC's breach scanner searches across more than 400 billion compromised records to find out whether your email address has appeared in data breaches, including this Total Swiss incident. If your contact information was part of this leak, be alert for unsolicited calls, emails, or messages that reference your Total Swiss account, and avoid clicking links in unexpected communications. Run a free scan at HEROIC.com to check whether your data has been compromised.
Breach Breakdown
1,381 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds