[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f16wxjoo40xdmu":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":17,"affectedCount":17,"affectedCountStatus":18,"affectedCountLowerBound":19,"affectedCountUnit":20,"hasEnglishDescription":4,"severity":21,"dataClasses":22,"description":28,"seoTitle":15,"seoTitleEn":29,"seoDescription":15,"seoDescriptionEn":30,"logoUrl":31,"isVerified":4,"isSensitive":32,"isSpamList":32,"isMalware":32,"company":33},"68e3266eda11adda48825301","omnicuris","Omnicuris Data Breach","omnicuris.com","2025-06-08T00:00:00.000Z","2025-07-13T06:00:49.000Z","2026-07-03T23:23:17.190Z","2026-07-18T23:55:40.888Z","Third party breach","",[],215298,"known",null,"unknown","High",[23,24,25,26,27],"Email addresses","Geographic locations","Names","Phone numbers","Professional skills","\u003Cp>The Omnicuris data breach is related to the disclosure of records belonging to healthcare professionals by the India-based continuing medical education platform in the June 2025 period. The scope includes approximately 215,298 records. This record was treated as a healthcare professional education platform breach; the company, country, sector, website, and data class fields were realigned with the verified scope. Since patient data was not verified, the sensitive flag was not raised.\u003C\u002Fp>\u003Cp>The text has been rewritten to directly explain risk, scope, and action to the user. The website domain was kept as omnicuris.com; a format that would cause https to appear twice in the link was not used since no protocol was added. The sector was kept as healthcare but clarified in the context of healthcare education and CME platform.\u003C\u002Fp>\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\u003Cp>The types of data seen in this record are email addresses, geographic locations, names, phone numbers, and professional areas of expertise. Password, patient record, or clinical data fields were not verified. Unverified payment card, bank account, private message, health record, or additional profile fields were not added to the data class list; only supported fields were left.\u003C\u002Fp>\u003Cp>The context of health expertise and educational advancement can be used in messages about fake conferences, training certificates, or professional memberships. An email address alone poses a risk of unwanted messages; when combined with a phone number, address, IP, date of birth, password, travel plans, partial card information, or device data, it becomes easier for an attacker to generate messages specific to the user. The risk assessment was conducted according to this combined effect.\u003C\u002Fp>\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>The scope was confirmed with record 215,298 dated June 2025. Confirmed areas were preserved while unconfirmed areas were excluded. The event was not combined with datasets of similar names, events from different periods of the same company, or incorrect industry attributions.\u003C\u002Fp>\u003Cp>The registration is limited to the domain name omnicuris.com and patient data was not presented as being violated. The domain name, company name, and industry information were kept in the narrowest accurate context possible. In areas of uncertainty, a verified flag or website domain was set accordingly; thus, no uncertain brand responsibility was shown to the user.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>User groups at risk may include doctors registered on the Omnicuris platform, healthcare professionals, and users who use educational content. Matched users should also assess other accounts where they use the same email, phone number, username, or password pattern outside of the relevant service.\u003C\u002Fp>\u003Cp>Professional title and position information can make targeted health education or certificate scams seem convincing. If there is a context of corporate email, educational account, hotel reservation, telecom subscription, gaming community, open-source donation, or tracking software, the social engineering risk may increase. Details that appear correct are not a sign of trust by themselves.\u003C\u002Fp>\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>Affected users should verify messages about training, certification, conferences, and professional memberships on the official platform. For records with a password field, all accounts using the same password should be updated; for records without a password field, focus should be on email, phone, fake notification, privacy, and identity matching risks.\u003C\u002Fp>\u003Cp>Instead of clicking on the links in the message, the address of the relevant service should be typed manually or the record in a trusted password manager should be used. Messages about shipping, account alerts, game rewards, support, donor notifications, travel reservations, security notifications, or subscription renewals should not be accepted without verification from an independent channel.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>Healthcare professionals should separate work and personal emails on education platforms and reduce unnecessary phone visibility. Users should regularly clean up old accounts, unnecessary profile fields, duplicate usernames, and outdated phone and address information. A unique password for each service and two-factor authentication wherever possible should be a fundamental rule.\u003C\u002Fp>\u003Cp>From the perspective of service providers, data minimization, strong password protection, monitoring of access logs, deletion of unnecessary fields, and having user notification processes ready are required. Even if health education platforms do not process patient data, they should carefully protect professional identity information. Accurate scope description is also part of the security work; exaggerated or incomplete information can mislead the user to take the wrong action.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>The user should primarily check with their email address in this record. If a match is found, it should be assumed that the phone, location, and professional expertise information can be used in targeted messages. The absence of a match does not completely rule out the use of a different email or the reuse of an old password; critical accounts should also be reviewed.\u003C\u002Fp>\u003Cp>This record remained verified; the patient data claim was not added. In this edit, the data fields were left as English canonical classes, the description visible to the user was written in Turkish and original, unverified fields were not added, and the sensitivity flag was used only when supported by the risk context.\u003C\u002Fp>","Omnicuris Data Breach (215.3 Thousand Reported Records)","Omnicuris Data Breach. 215.3 Thousand reported records were reported. Reported data: Email addresses, Geographic locations, Names. Review the scope, risks…","\u002Fuploads\u002Flogo\u002Fomnicuris_com.webp",false,{"name":34,"sector":35,"country":36,"website":9,"websiteArchiveUrl":15,"websiteStatus":15,"websiteCheckedAt":19},"Omnicuris","Healthcare Education \u002F CME Platform","India"]