● Data Breaches

Moroccan Medical Provider Distamed Allegedly Breached, 13 Years of Patient Data Claimed

July 24, 2026 · snewle
Moroccan Medical Provider Distamed Allegedly Breached, 13 Years of Patient Data Claimed

A Moroccan medical equipment provider has allegedly suffered a data breach exposing patient records and company archives spanning more than a decade. A threat actor using the handle anisanas2 posted on July 24, 2026, claiming to possess data from Distamed, a healthcare and medical devices company operating in Morocco. The Distamed data breach allegedly includes patient information dating back to 2013, though no specific record count has been disclosed.

What Data Was Allegedly Compromised?

According to the threat actor’s claims, the exposed data includes comprehensive patient records containing full names, CIN national identification numbers, phone numbers, home addresses, age, and dates of visits. The alleged breach also encompasses full client lists, billing documents, invoices, document scans, and internal company files. Additionally, the actor claims the dataset contains government contract dealings and military hospital records.

The alleged archive reportedly spans 13 years of company operations, potentially affecting anyone who interacted with Distamed since 2013. The provider’s specialization in cardiology, pulmonology, neurology, and sleep diagnostics means that patient records alone could reveal sensitive health conditions even without explicit diagnosis fields.

Why Are Moroccan CIN Numbers Particularly Sensitive?

The inclusion of CIN national identification numbers represents a significant risk factor for affected individuals. These identifiers form the foundation of Moroccan identity verification systems and underpin access to banking services and government programs. When combined with names, addresses, and phone numbers, this information creates a complete identity profile that cannot be changed or revoked after exposure.

Healthcare data carries unique risks because unlike passwords or credit card numbers, medical information cannot be reissued or meaningfully mitigated once published. The 13-year timeframe potentially expands the affected population well beyond current patients to include anyone who received services during that period.

What Are the National Security Implications?

The claimed inclusion of military hospital records and government contract documentation introduces concerns beyond patient privacy. Procurement records, equipment inventories, and facility documentation for military medical infrastructure could carry national security relevance independent of the patient data itself. Such information might attract attention from parties without commercial motivations.

Has the Breach Been Verified?

The breach remains unverified as of the posting date. The threat actor provided no sample data, record count, or file listing in the public post, offering only field descriptions behind a reply-or-upgrade access gate. This represents less substantiation than typically seen in comparable breach claims. The threat actor anisanas2 is described as an established forum account with moderate history and elevated standing who promotes external contact channels. Distamed has not publicly addressed the allegations.

Source: Dark Web Informer