Rhysida leaks MPA Pharma data trove
The Rhysida ransomware group posted ~5.8TB (2.9M files) of stolen data from German pharma distributor MPA Pharma GmbH on its leak site.
Ransomware.live's victim listing documents that the Rhysida ransomware group has claimed MPA Pharma GmbH, a German importer/distributor of patented and generic pharmaceuticals, as a victim, publishing roughly 2.9 million files (~5.8TB) as proof of a double-extortion attack. The leaked categories described include accounting and SQL general-ledger backups (17.7M rows), government audit records (customs, corporate tax, social security, wage tax), narcotics/BtM permits and reconciliation data covering controlled substances (fentanyl, hydromorphone, oxycodone, tapentadol) with documented reconciliation gaps from 2017-2020, litigation files (including Merck/MSD and Amgros matters), corporate ownership/UBO and nominee-structure documents, executive personal data including credit card details with CVV, ID documents, and a centralized 'Tier 1' credentials/password report.
No technical details on the initial intrusion vector, malware samples, or infrastructure used in the compromise are provided in this listing, so defenders cannot derive IOCs or a specific detection signature from this report alone. The breach is notable for its scope and sensitivity — regulated narcotics tracking data, tax/audit records, and a consolidated password list — which raises risk of follow-on fraud, regulatory scrutiny, and further targeting of MPA Pharma's executives, partners (Eli Lilly, AstraZeneca, Amgros), and possibly affiliated entities named in the leak (e.g., Paranova Pack B.V.). Organizations in the pharmaceutical/healthcare supply chain, particularly those with narcotics handling and multinational corporate structures, should treat this as a reminder to audit exposure of financial backups, credential stores, and controlled-substance documentation, and to monitor for secondary use of leaked credentials or personal data.
Mentioned in this report
Source reporting: https://www.ransomware.live/id/TVBBIFBoYXJtYUByaHlzaWRh
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free