Search TorNews

Find cybersecurity news, guides, and research articles

Popular searches:

Home » News » Data Breaches » French Healthcare Provider Orkyn Confirms Breach Exposing Sensitive Patient Data

French Healthcare Provider Orkyn Confirms Breach Exposing Sensitive Patient Data

Last updated:October 4, 2026
Human Written
  • A hacker claims to have stolen almost 18,000 patient files from Orkyn, a French home healthcare company.

  • The leaked data reportedly includes names, social security numbers, home addresses, and medical treatment details.

  • Orkyn says the breach did not touch the medical devices patients use at home.

Hacker Claims Nearly 18,000 Orkyn Patient Records Stolen in French Cyberattack

A hacker says they broke into Orkyn, a company that helps patients get medical care at home in France. The attacker now claims to have close to 18,000 patient files.

They are offering these files for download, according to Cyberattaque.org, a site that tracks cyberattacks. Orkyn confirms the attack happened, but the company has not shared an exact number of affected patients.

Orkyn provides care for people who need medical equipment or treatment at home. Services include breathing support, nutrition help, and diabetes care. The company is part of Air Liquide Healthcare, which also runs VitalAire and Dinno Santé. Air Liquide says its health branch supports over 500,000 patients across France.

A Breach that Reached Deep Into Patient Files

Orkyn first noticed the attack on September 19, 2026. The company quickly shut down its patient website, called “Orkyn & moi.” It wanted to check how safe the site was before letting people log in again.

Orkyn sent an email to affected patients. Cyberattaque.org says it obtained a copy of that email. The message confirms that outsiders got into a file holding personal information.

The stolen data covers basic identity details. This includes each patient’s name, sex, and date of birth. It also includes social security numbers, home addresses, emails, and phone numbers. An internal patient code was exposed too.

The leak goes beyond simple contact details, though. Orkyn confirms that medical care information was also exposed. This includes visit dates and notes written by staff. The files name each patient’s prescribing doctor. They also show when a prescription ends.

More sensitive records were part of the leak as well. Orkyn confirms exposure of data about equipment delivery and setup. The files reveal whether a patient uses remote monitoring. They also show details about a patient’s therapy and how well they follow their treatment plan. Some billing information sent to France’s health insurance system was exposed too, including certain treatment billing codes.

Orkyn has not explained how the hackers broke in. The company only says that outside parties reached a data file despite its security tools. Nobody yet knows if the attackers used stolen passwords, a software flaw, or another method.

Home Medical Devices were Not Affected, Orkyn Says

Many Orkyn patients rely on medical equipment installed in their homes. This raised a serious concern after the breach became known.

Orkyn says the breached database has no technical link to those home devices. The company states the equipment runs on its own separate system. This means the machines kept working as normal throughout the incident.

This breach was not an isolated event for Air Liquide Healthcare. Just days earlier, on September 19, a hacker claimed to have stolen 50,000 patient files from VitalAire’s extranet system, a sister brand under the same parent company. That earlier claim had not been confirmed by VitalAire at the time it was first reported. No public link has been drawn between the two cases so far.

A Risk That Goes Beyond Stolen Contact Information

Health data like this can cause real harm if it falls into the wrong hands. A mix of identity details, Social Security numbers, and medical history gives criminals strong material to work with.

Other dark web investigations have uncovered the misuse of sensitive personal material, including a case where a Scottish care worker shared child abuse fantasies on the dark web, according to investigators.

Scammers could use this information to send fake emails or texts. A message mentioning a real doctor’s name or a recent appointment can feel very convincing. This makes phishing attempts harder to spot.

Criminals might also try identity theft using the stolen Social Security numbers. Someone could pretend to be a health worker or an insurance agent during a phone call. Knowing a patient’s treatment history makes that trick more believable.

Orkyn has not confirmed the exact number of people affected by the breach. The hacker’s claim of nearly 18,000 profiles has not been independently verified by an official source. Orkyn is urging patients to stay alert for strange emails, texts, and phone calls.

Patients who think they might be affected should watch their email and phone closely. Avoid clicking links from unknown senders. Confirm any unusual message directly with Orkyn using contact details from its official website rather than the message itself.

The investigation into the Orkyn breach is still ongoing. The full number of affected patients and the exact method the hackers used remain unclear for now.

Share this article

About the Author

Memchick E

Memchick E

Digital Privacy Journalist

Memchick is a digital privacy journalist who investigates how technology and policy impact personal freedom. Her work explores surveillance capitalism, encryption laws, and the real-world consequences of data leaks. She is driven by a mission to demystify digital rights and empower readers with the knowledge to protect their anonymity online.

View all posts by Memchick E >
Comments (0)

No comments.