Back to Exposure Report
Healthcare / Medical DevicesAugust 2, 2026Switzerland / Global

Alcon

Twenty-five million Salesforce records. Two days to make contact. Whether those records contain patient data or business contacts decides which law applies — and Alcon has 48 hours to find out.

Claims unverifiedSalesforce CRM records (claimed)Personally identifiable information (claimed)Internal files (claimed)
1

What happened?

On August 2, 2026, the ShinyHunters extortion group listed Alcon, the Swiss eye care company, on its leak site. The listing states that internal files were exfiltrated and claims more than 25 million Salesforce records containing personally identifiable information were compromised. The group gave Alcon until August 4 to make contact, warning of a public leak and, in its phrasing, additional "annoying digital problems."

Alcon was listed alongside Questel and Lumenis in the same period. The claim is unverified; no data sample or forensic detail accompanied it, and ShinyHunters has a documented history of inflated volume claims. Alcon makes surgical equipment and contact lenses and operates in more than 60 countries.

2

What data was actually inside?

The specific data types have not been publicly disclosed or verified. The only characterisation available is the attacker's: Salesforce records containing some personally identifiable information, plus internal files.

What can be stated without speculation is that a CRM at Alcon's scale serves several distinct populations. Eye care professionals and surgical practices are business contacts. Distributors and procurement contacts are commercial relationships. But a company selling contact lenses direct to consumers and running patient support around surgical products will also hold individual records — and whether those individuals are described in clinical terms is the question that determines everything downstream.

3

Who gets hurt and how?

If the records are predominantly professional contacts, the harm is targeted phishing against ophthalmologists and optometrists — credible, damaging, but bounded, and the affected parties are institutions with their own defenses.

If the records include consumer or patient data, the harm changes character. A contact lens prescription is health information. Enrollment in a support program around a surgical product discloses that a person had eye surgery. Vision correction data is not the most sensitive health category, but it is health data, and it is attached to named individuals who never considered that buying lenses created a medical record held by a manufacturer.

Neither Alcon nor the public can currently say which of those two descriptions is accurate. That uncertainty is itself the harm to the affected people, who cannot assess their own exposure.

4

What did they think they were doing right?

While not publicly confirmed for Alcon specifically, a Swiss-listed medical device manufacturer operating in 60-plus countries maintains GDPR compliance programs, medical device regulatory quality systems, and the security controls that enterprise Salesforce deployments support — field-level encryption, permission sets, event monitoring.

The recurring assumption is architectural rather than technical: the CRM is understood as a sales system. It is procured by commercial functions, administered by a sales operations team, and governed accordingly. The privacy program focuses on the systems that were designed to hold personal data — the clinical registry, the patient support platform, the HR system. The CRM is where the customers live, and customers are a marketing concern.

5

What did they not know about their own data?

This is the fourth Salesforce-tenant extortion claim to appear in this series recently, and the pattern is consistent enough to name. A CRM tenant accumulates for a decade or more. Each addition is justified locally — a campaign needs a field, an acquisition merges an org, a support integration writes case data back, a marketing automation tool syncs a list. No single decision is unreasonable. Nobody ever audits the aggregate.

The result is a system nobody classified as a regulated data store, holding whatever fifteen years of business activity deposited in it. When an extortion group names a record count, the company genuinely cannot immediately confirm or deny it, because the honest answer to "what is in our CRM?" is "more than anyone has counted."

Alcon has 48 hours to determine whether 25 million records exist in its tenant and what they contain. That is a data inventory question, and it is being asked at the worst possible time.

If you use Salesforce, you probably have the same data types—emails, names, addresses, phone numbers. Do you know which fields contain PII?

6

What does attribution look like the morning after?

The regulatory analysis forks on the data classification. GDPR applies to EU data subjects with a 72-hour notification deadline to the supervisory authority from awareness — and if any records constitute health data under Article 9, the special category provisions raise both the obligation and the penalty exposure. Swiss data protection law applies at home. US state statutes apply to American individuals, and HIPAA could apply to any records where Alcon acts as a business associate to a covered entity.

Alcon cannot select the right regime until it knows what is in the tenant, and the 72-hour GDPR clock does not pause for that determination. Operating in more than 60 countries means the same analysis repeats across dozens of jurisdictions with incompatible definitions of personal and health data. Meanwhile the extortion deadline was two days, which means the leak decision arrives well before the classification work concludes.

7

What would have changed the outcome?

A current classification of the CRM tenant — what data types it holds, for which populations, in which jurisdictions — so a 25 million record claim could be evaluated in hours rather than guessed at.

The extortion model depends on the victim's uncertainty. A company that knows its tenant holds 4 million business contacts and no health data can say so immediately, publicly, with evidence, and the leverage collapses. A company that cannot must negotiate against its own ignorance. Your CRM has been collecting records for a decade under the governance of whichever team happened to own it. The question is not whether it is secure. It is whether anyone can currently say what is in it. See also the Brinks Home Salesforce listing and the RingCentral extortion claim.

Alcon found out the hard way.

Your team could spend the next 6 months rebuilding systems, notifying customers, and answering legal questions. Or you could spend 24 hours finding out what's actually at risk.