2026 Call-On-Doc — 1.14M patient records (dark web sale)
Data compromised
Names, addresses, phones, emails, medical conditions, prescriptions, payment amounts
Technical writeup
Call-On-Doc telehealth platform suffered breach in December 2025. Threat actor 'iProfessor' listed stolen database for $5,000 on dark web Jan 22, 2026. 1,144,223 patient records. Exposed: names, addresses, phones, emails, medical categories, conditions (including STD diagnoses), prescriptions, amounts paid. No encryption on stolen data; company did not detect attack. Company has not publicly commented.
Root cause
Unauthorized database access; offered for sale on dark web
References
- https://www.upguard.com/news/callondoc-data-breach-2026-01-22
- https://databreaches.net/2026/01/24/call-on-doc-allegedly-had-a-breach-affecting-more-than-1-million-patients-theyve-yet-to-comment/
- https://darkwebinformer.com/callondoc-telemedicine-platform-allegedly-breached-exposing-1-14-million-patient-records-including-medical-conditions/