Pharmaceutical

Industry

Databreach Impacts Business Operations at Sun Pharmaceutical

March 2, 2023

A ransomware group has claimed responsibility for ‘IT security incident’ at Sun Pharma whose effect included breach of certain file systems and the theft of certain company data and personal data, the drugmaker said in a stock exchange filing. “As part of the containment measures, we proactively isolated our network and initiated the recovery process. As a result of these measures, Company’s business operations have been impacted,” it said. “Consequently, revenues are expected to be reduced in some of our businesses. The Company would incur expenses in connection with the incident and the remediation.”

Sun Pharma first reported the incident on March 2. Back then it said that the incident did not affect Sun’s core systems and operations. On March 27 the company said it is currently unable to determine other potential adverse impacts of the incident.

read more

Covid vaccine-maker Dr Reddy Laboratories hit by cyber-attack

October 22, 2020

Pharmaceutical company Dr Reddy’s, which is developing a Covid-19 vaccine, stated it has been hit by a cyber-attack. Sites around the world have been affected, including those in the UK, Brazil, India, Russia and the US. The India-based company said it had isolated all of its data centre services to contain the attack. The attack came only days after the pharmaceutical company was gearing up for a phase 2/3 clinical trial of Russia’s COVID-19 vaccine, dubbed Sputnik V, after gaining the trial go-ahead from Indian regulators last week.

read more

Novartis claims no sensitive data breach in latest cyberattack by Industrial Spy.

February 25, 2022

June 2022: Pharmaceutical giant Novartis says no sensitive data was compromised in a recent cyberattack by the Industrial Spy data-extortion gang. Industrial Spy is a hacking group that runs an extortion marketplace where they sell data stolen from compromised organizations. On June 2, 2022 the hacking group began selling data allegedly stolen from Novartis on their Tor extortion marketplace for $500,000 in bitcoins. The data being sold consists of 7.7 MB of PDF files, which all have a timestamp of 2/25/2022 04:26, likely when the data was stolen. As the amount of data for sale is minimal, it is not clear if this is all the threat actors stole or if they have further data to sell later.

Novartis declined to answer any further questions about the breach, when it occurred, and how the threat actors gained access to their data.

read more

Pharma Service Provider Hit in Cyber Attack

September 27, 2021

Digital prescription fulfillment provider, Ravkoo, suffered a cybersecurity incident this past September where an unauthorized third party infiltrated the company’s AWS cloud portal affecting 105,000 of its customers.
On September 27, Auburndale, Florida-based Ravkoo fell victim to a cybersecurity incident, which may have exposed prescription and health information located on the AWS portal, according to the letter to the New Hampshire Attorney General signed by Ross M. Molina of Wilson Elser Moskowitz Edelman & Dicker LLP.

read more

Supernus Pharma Hit in Ransomware Attack

November 14, 2021

Rockville, Maryland-based Supernus Pharmaceuticals, Inc., a biopharmaceutical company, said Wednesday it was a target of a ransomware attack.
The attack, which started November 14, had no significant impact on the business and did not cause any serious disruption to the company’s operations, officials said in an advisory. The company added it continues to operate without interruption and does not currently anticipate paying any ransom amounts to any criminal ransomware group.

read more

Ethernet Network Storm Zaps Multiple PLC5’s

January 1, 2003

WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.

read more

Hacker froze operations at pharmaceutical company

January 1, 2011

WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.

read more

Fresenius Kabi Computer Virus

May 6, 2020

A computer virus infected at least one of its businesses’ IT systems. The corporation said the security incident had hampered some production in its pharmaceutical business, which makes everything from nutritional products and infusion therapies to pain relievers that are in high demand during the coronavirus pandemic

read more

Merck Ransomware Attack

September 27, 2017

Crippled more than 40,000 laptop and desktop computers, as well as 7,500 servers,. Crippled Merck’s production facilities. Cost the company $1.3Billion.

read more