[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2oneck71julfr":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"publishedAt":12,"modifiedDate":13,"contentUpdatedAt":14,"source":15,"sourceUrl":16,"sourceUrls":17,"pwnCount":19,"affectedCount":19,"affectedCountStatus":20,"affectedCountLowerBound":12,"affectedCountUnit":21,"hasEnglishDescription":4,"contentLocale":22,"availableLocales":23,"translations":25,"severity":28,"dataClasses":29,"description":38,"seoTitle":8,"seoDescription":39,"logoUrl":40,"isVerified":4,"isSensitive":4,"isSpamList":41,"isMalware":41,"company":42},"6a452308a20f867c8ba8e719","gemotest","Медицинская лаборатория Гемотест (Gemotest) Data Breach","gemotest.ru","2022-04-22T00:00:00.000Z","2025-12-24T02:40:40.000Z",null,"2026-07-03T09:51:09.673Z","2026-07-19T00:02:40.980Z","Third party breach","https:\u002F\u002Fwww.zataz.com\u002Fle-laboratoire-gemotest-pirate-31-millions-de-patients-concernes\u002F",[16,18],"https:\u002F\u002Fgxpnews.net\u002Fen\u002F2022\u002F07\u002Fgemotest-to-pay-a-rur-60000-fine-for-customer-personal-data-leakage\u002F",6341495,"known","unknown","en",[22,24],"tr",{"en":26,"tr":27},{"slug":7},{"slug":7},"Critical",[30,31,32,33,34,35,36,37],"Dates of birth","Email addresses","Genders","Government issued IDs","Health insurance information","Names","Passport numbers","Physical addresses","\u003Cp>The Gemotest data breach is a verified incident from April 2022 affecting the personal and health-related identity data of patients using Russia-based medical laboratory services. The incident was reported to impact 31 million people in terms of broad patient data, and the verifiable scope searchable by email was determined as 6,341,495 unique records. The affected data groups include birth dates, email addresses, gender information, official identity information, health insurance information, names, passport numbers, and physical addresses. These records are highly sensitive because when healthcare, identity document, insurance, and address data are combined, the risk of identity verification issues, false health claims, and insurance fraud increases. Passwords, payment cards, bank accounts, test result content, or medical report texts are not among the verified data categories for this record.\u003C\u002Fp>\n\u003Ch2>Types of Leaked Data and Their Risks\u003C\u002Fh2>\n\u003Cp>The most critical risk in the Gemotest record is the combination of identity and health insurance-related data. When name, date of birth, gender, passport number, official ID field, and physical address are considered together, the potential for misuse in identity verification processes increases. Health insurance information can also be used in fraud scenarios such as fake appointments, fake invoices, insurance claims, or notifications to healthcare institutions.\u003C\u002Fp>\n\u003Cp>When email addresses are combined with this data set, the risk of targeted messaging increases. Attackers may send messages that appear to be test results, laboratory notifications, appointment changes, insurance updates, or payment alerts. Fields such as physical address and passport information can affect not only online security but also real-world identity security. In this incident, although a password leak has not been confirmed, the risk to identity and health data could be much longer lasting.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>For this record, the verifiable number reachable by email should be maintained as 6,341,495. Referring to 31 million patient records in a broader event context does not mean that this number represents the count of email matches. Each record may not correspond to a single real person; there may be duplicates for the same patient, old contact information, or different service records. Therefore, the broader patient impact and email coverage should be described separately in the text.\u003C\u002Fp>\n\u003Cp>Verified data categories are birth dates, email addresses, gender information, official identification information, health insurance information, names, passport numbers, and physical addresses. Passwords, password hashes, payment cards, bank accounts, phone numbers, test result texts, diagnosis information, prescriptions, doctor notes, or medical reports should not be added to the record unless verified. Although the healthcare context is important, unverified medical content fields should not be communicated to the user.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>The highest risk is for patients who have used Gemotest services and whose passport, insurance, or address information is recorded along with their email address. Health insurance and identity information can be used in attempts of fraudulent healthcare services, insurance claims, identity verification, and financial fraud. Fields such as address and date of birth can also affect security questions or manual verification processes in other services.\u003C\u002Fp>\n\u003Cp>Elderly users, individuals who regularly undergo medical tests, users booking appointments on behalf of family members, and patients dealing with health insurance should also be cautious. These people may be more likely to believe fake messages that appear to come from a laboratory, insurance company, or healthcare institution. When an email address and identity context are present together, attackers can personalize the message for the individual. Therefore, a user in a positive match situation should not only check email security but also monitor identity and insurance processes.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>The user with an email address in this record should carefully check all messages related to health services or insurance. When test results, appointments, payments, insurance updates, or document verification links are received, the official address of the institution should be typed manually or a known phone channel should be used instead of clicking the direct link. Emails and messages requesting passport or official identification information should be considered suspicious.\u003C\u002Fp>\n\u003Cp>Multi-factor authentication should be enabled on the email account, and account recovery options should be updated. The user should monitor whether there are any unexpected insurance claims, healthcare applications, credit applications, or address change notifications opened in their name. Due to the potential misuse of passport and official ID data, identity protection, alert, or application verification services offered by relevant institutions should be regularly monitored.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>The Gemotest incident shows that the identity and insurance information collected in healthcare services carry long-term risks. Users should consider using separate email addresses for health, insurance, and financial accounts, keep multi-factor authentication enabled on critical accounts, and verify digital requests requiring identity documents through an independent channel. Since information such as address, date of birth, and passport details are difficult to change, the risk can persist for years.\u003C\u002Fp>\n\u003Cp>The core lesson for healthcare service providers is that patient data should be stored to the minimum necessary extent, and access to fields such as identity, insurance, and address should be strictly restricted. Access logs should be monitored, data retention periods reviewed, and in incident reports, which non-health identity fields are affected should be clearly stated. If medical content such as test results or diagnoses has not been verified, this limit should be clearly explained to the user.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>During record verification for a Gemotest breach, the result indicates whether the entered email address is found in this verified dataset. If the result is positive, the email address, name, date of birth, gender, official identification details, passport number, health insurance information, and physical address risk should be assessed together. If the result is negative, it means that no match was found in this specific email dataset; this does not prove that the person is not included in a broader patient archive or other health data incidents.\u003C\u002Fp>\n\u003Cp>The correct user action is to strengthen email security, verify health and insurance-themed messages through an independent channel, carefully examine requests for identification documents, monitor unexpected insurance or health transactions, and conduct long-term monitoring for signs of fraud related to official identity information. This record is not a short-term risk like a password breach; due to the context of identity, address, and health insurance, it requires ongoing attention.\u003C\u002Fp>","Медицинская лаборатория Гемотест (Gemotest) Data Breach. 6.3 Million reported records are reported. Reported data: Dates of birth, Email addresses, Genders…","\u002Fuploads\u002Flogo\u002Fgemotest_ru.webp",false,{"name":43,"sector":44,"country":45,"website":9,"websiteArchiveUrl":46,"websiteStatus":46,"websiteCheckedAt":12},"Медицинская лаборатория Гемотест (Gemotest)","Medical Laboratory","Russia",""]