# Rhysida leaks MPA Pharma data trove

Published: 2026-09-18 · Severity: elevated · Sectors: healthcare
Canonical: https://vorant.io/reports/e6f4ded5-36cc-50b9-8854-c33353e9db82/rhysida-leaks-mpa-pharma-data-trove

> The Rhysida ransomware group posted ~5.8TB (2.9M files) of stolen data from German pharma distributor MPA Pharma GmbH on its leak site.

Ransomware.live's victim listing documents that the Rhysida ransomware group has claimed MPA Pharma GmbH, a German importer/distributor of patented and generic pharmaceuticals, as a victim, publishing roughly 2.9 million files (~5.8TB) as proof of a double-extortion attack. The leaked categories described include accounting and SQL general-ledger backups (17.7M rows), government audit records (customs, corporate tax, social security, wage tax), narcotics/BtM permits and reconciliation data covering controlled substances (fentanyl, hydromorphone, oxycodone, tapentadol) with documented reconciliation gaps from 2017-2020, litigation files (including Merck/MSD and Amgros matters), corporate ownership/UBO and nominee-structure documents, executive personal data including credit card details with CVV, ID documents, and a centralized 'Tier 1' credentials/password report.

No technical details on the initial intrusion vector, malware samples, or infrastructure used in the compromise are provided in this listing, so defenders cannot derive IOCs or a specific detection signature from this report alone. The breach is notable for its scope and sensitivity — regulated narcotics tracking data, tax/audit records, and a consolidated password list — which raises risk of follow-on fraud, regulatory scrutiny, and further targeting of MPA Pharma's executives, partners (Eli Lilly, AstraZeneca, Amgros), and possibly affiliated entities named in the leak (e.g., Paranova Pack B.V.). Organizations in the pharmaceutical/healthcare supply chain, particularly those with narcotics handling and multinational corporate structures, should treat this as a reminder to audit exposure of financial backups, credential stores, and controlled-substance documentation, and to monitor for secondary use of leaked credentials or personal data.

## Mentioned in this report

- Threat actors: rhysida
- Malware: Rhysida

Source reporting: https://www.ransomware.live/id/TVBBIFBoYXJtYUByaHlzaWRh

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/e6f4ded5-36cc-50b9-8854-c33353e9db82/rhysida-leaks-mpa-pharma-data-trove.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
