← MiniMed Panama

2026 MiniMed Panama - alleged default-credential compromise exposing PHI and credentials

2026 400.0K records affected Share on X

Data compromised

Alleged patient IDs, names, gender, emails, phone numbers, addresses, dates of birth, nationality, medical-exam metadata, staff details, user credentials/passwords, appointments, and payment-method metadata

Technical writeup

VECERT Analyzer reported on X that a threat actor using the handle ohmydays, affiliated with Waxx Org, claimed to have compromised MiniMed Panama through default credentials used by a technology provider. The post characterized the exposure as an entire database of roughly 400,000 records, including patient data, medical exams/images, staff records, system users, and appointments. The post was marked as intelligence reporting and should be treated as unverified until MiniMed or regulators confirm details.

Root cause

Alleged default credentials at a technology-provider-managed system

References