The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Pharmaceuticals
Breach intelligence, attack campaigns, and threat reports targeting the Pharmaceuticals sector.
Explore Other Sectors
Pharmaceuticals Threat Reports
Veradigm Breach Exposes Critical Gaps in Healthcare API Security
In September 2026, healthcare technology company Veradigm disclosed a significant data breach affecting 3.5 million patient records after The Gentlemen ransomware group compromised a third-party vendor's credentials. The attackers gained access to a limited Veradigm API interface, exfiltrating personal information including names, addresses, Social Security numbers, and contact details. While clinical data remained secure, the incident exposed critical vulnerabilities in third-party vendor access controls and API security frameworks. This incident highlights the growing threat of supply chain attacks targeting healthcare organizations, coinciding with increased ransomware activity against medical providers and stricter regulatory scrutiny under evolving HIPAA enforcement priorities.
2 weeks ago
Kill Chain
Critical DoS Vulnerability Exposes Rockwell Automation Industrial Controllers to Remote Attack
A critical denial-of-service vulnerability (CVE-2026-9637) affects multiple Rockwell Automation Logix Platform controllers including ControlLogix 5580, CompactLogix 5380, GuardLogix 5580, and Compact GuardLogix 5380 systems. The vulnerability stems from improper validation of input length during Common Industrial Protocol (CIP) message processing, allowing remote attackers to trigger a major nonrecoverable fault (MNRF) that requires a complete power cycle to restore operations. Affected versions span firmware releases up to V33 and specific ranges in V34-V36 branches, impacting critical manufacturing infrastructure worldwide. This vulnerability highlights the ongoing targeting of industrial control systems and the critical need for robust OT security measures. As industrial networks become increasingly connected and Nation-state actors continue to probe critical infrastructure, vulnerabilities in widely-deployed platforms like Rockwell's Logix controllers represent significant national security and operational continuity risks that require immediate attention.
3 weeks ago
Kill Chain
McKesson's $55M Data Extortion: How ShinyHunters Exploited Healthcare's Cloud Vulnerabilities
In August 2024, McKesson Corporation, a major healthcare distributor handling one-third of North America's pharmaceuticals with $403.4 billion in revenue, suffered a sophisticated data extortion attack by the ShinyHunters cybercrime group. The attackers gained access to third-party applications between August 21-25, stealing sensitive data from oncology, multispecialty, and medical-surgical business units. ShinyHunters demanded over $55 million in ransom and threatened to leak stolen data by September 1, 2024, demonstrating their typical social engineering tactics to exploit identity and access management weaknesses in cloud-hosted environments. This incident highlights the escalating threat of data extortion campaigns targeting critical healthcare infrastructure, as ShinyHunters continues their spree of high-profile attacks against cloud platforms including Oracle, Salesforce, and Snowflake, exploiting valid credentials to evade traditional security controls.
3 weeks ago
Kill Chain
Boston Scientific Cyberattack Disrupts Global Medical Device Operations
On August 25, 2026, Boston Scientific, a major medical device manufacturer with $20 billion in annual revenue, suffered a cyberattack that disrupted IT systems and caused global operational outages. The incident impacted critical business applications and halted the company's ability to process and ship customer orders across its 127-country presence. While the attack vector and threat actor remain undisclosed, the company activated incident response procedures and engaged external cybersecurity experts for containment and investigation efforts. The attack highlights the increasing threat to critical healthcare infrastructure and medical device supply chains. Healthcare organizations face heightened risks as ransomware groups target high-value entities with essential services, potentially affecting patient care and medical device availability worldwide.
4 weeks ago
Kill Chain
Ukraine's Crackdown on 94 Fraudulent Call Centers in 2026
In August 2026, Ukrainian authorities conducted a large-scale operation resulting in the shutdown of 94 fraudulent call centers across the country. These centers engaged in various schemes, including posing as bank officials to extract sensitive financial information and luring victims into fake investment platforms. The coordinated effort involved 411 searches and led to the seizure of significant assets, including $2 million in cash, 64,000 euros, and 1 kilogram of gold. Additionally, 26 individuals were formally identified as suspects in connection with these fraudulent activities. This incident underscores a growing trend of sophisticated social engineering attacks targeting individuals and organizations. The scale and coordination of these fraudulent operations highlight the urgent need for enhanced cybersecurity measures and public awareness to combat such threats effectively.
1 month ago
Kill Chain
Amgen's 2026 Cloud Data Breach: A Wake-Up Call for Healthcare Cybersecurity
In July 2026, Amgen, a leading biotechnology company, detected unauthorized access to its cloud environments managed by third-party service providers. The breach resulted in the exfiltration of proprietary data and patient protected health information. Amgen promptly activated its cybersecurity response plan, implemented containment measures, and engaged independent forensic experts to investigate the incident. The company is assessing the full scope of the breach, including potential exposure of confidential business information, intellectual property, and additional patient data. This incident underscores the escalating risks associated with third-party cloud services in the healthcare sector. Organizations must enhance their security postures by implementing robust access controls, continuous monitoring, and comprehensive incident response strategies to mitigate potential threats.
1 month ago
Kill Chain
Critical Authentication Bypass Vulnerability in Siemens Opcenter X (CVE-2026-56451)
In July 2026, Siemens disclosed a critical vulnerability (CVE-2026-56451) in Opcenter X versions prior to V2604. The flaw arises from improper validation of the algorithm specified in the JSON Web Token (JWT) header, allowing unauthenticated remote attackers to forge arbitrary JWTs. This vulnerability enables attackers to bypass authentication mechanisms and impersonate any user, including administrative accounts, potentially granting full unauthorized access to the application. Siemens has released version V2604 to address this issue and recommends immediate updates. ([cert-portal.siemens.com](https://cert-portal.siemens.com/productcert/html/ssa-096828.html?utm_source=openai)) This incident underscores the critical importance of robust cryptographic validation in authentication processes. As cyber threats evolve, organizations must ensure that their applications rigorously enforce security protocols to prevent unauthorized access and data breaches.
2 months ago
Kill Chain
Abbott Laboratories Faces Cyber Attacks: ShinyHunters' Vishing Tactics in 2026
In July 2026, Abbott Laboratories disclosed two separate cybersecurity incidents. The first involved unauthorized access to internal systems within its Cancer Diagnostics business, attributed to the ShinyHunters extortion group. The attackers reportedly used a vishing attack in mid-June to compromise a Microsoft Entra single sign-on account, leading to data exfiltration. The second incident pertained to a potential breach of Abbott's LabCentral portal, with claims of stolen company data. Abbott stated that these incidents did not impact business operations, product availability, or patient services, and that the affected systems were separate from its core infrastructure. These incidents underscore the escalating threat posed by sophisticated social engineering attacks targeting healthcare organizations. The ShinyHunters group has been increasingly active, employing tactics like vishing to exploit single sign-on vulnerabilities, highlighting the need for enhanced security measures and employee awareness training to mitigate such risks.
2 months ago
Kill Chain
Interpol Impersonation Ransomware Targets Small Businesses in 2026
In July 2026, a ransomware campaign targeted small businesses across multiple regions, including the US, Europe, Asia, and the Middle East. Attackers impersonated Interpol officials, sending phishing emails that claimed the recipient's organization was under investigation for suspicious activity. These emails urged recipients to download a password-protected archive from Proton Drive, purportedly containing evidence. Upon opening, the archive delivered a ransomware payload disguised as a video file, encrypting local systems and prompting victims to contact the attackers via the Tox messaging platform to negotiate payment. ([darkreading.com](https://www.darkreading.com/cyberattacks-data-breaches/attackers-use-interpol-lure-target-small-businesses?utm_source=openai)) This incident underscores the increasing trend of cybercriminals leveraging social engineering tactics to exploit small businesses, which often lack dedicated cybersecurity resources. The campaign highlights the need for heightened awareness and robust security measures to defend against such deceptive attacks.
2 months ago
Kill Chain
Medtronic Data Breach: ShinyHunters Claims 9 Million Records Stolen
In April 2026, Medtronic, a leading global medical device manufacturer, detected unauthorized access to its corporate IT systems. The cybercriminal group ShinyHunters claimed responsibility, alleging the theft of over 9 million records containing personally identifiable information (PII) and internal corporate data. Medtronic confirmed the breach but has not verified the exact number of records compromised. The company assured that the incident did not impact product security, patient safety, or operational systems. Investigations are ongoing to determine the full scope of the data accessed. This incident underscores the persistent threat posed by cyber extortion groups targeting critical infrastructure sectors. The healthcare industry, in particular, remains a prime target due to the sensitive nature of the data it handles. Organizations must continually enhance their cybersecurity measures to protect against such sophisticated attacks.
2 months ago
Kill Chain
Critical Vulnerability in pydicom's pynetdicom Library Exposes Healthcare Systems
In June 2026, a critical vulnerability (CVE-2026-56445) was identified in the pydicom pynetdicom library, specifically affecting versions from 1.0.0 up to and including 3.0.4. This flaw resides in the qrscp application's C-STORE handler, which improperly handles attacker-supplied DICOM datasets, allowing unauthenticated attackers to write files to arbitrary paths on the server. The vulnerability poses significant risks, particularly to the healthcare sector, as it could lead to unauthorized data manipulation or system compromise. The maintainers of pynetdicom have not yet released a fix for this vulnerability. Organizations utilizing affected versions are advised to restrict network exposure of the qrscp DICOM port (default 11112) to trusted peers, implement firewall protections, and monitor for updates from the project's repository. This incident underscores the importance of securing medical imaging software against potential cyber threats.
2 months ago
Kill Chain
Novo Nordisk 2026 Breach: A Wake-Up Call for Software Development Security
In March 2026, Novo Nordisk, a leading pharmaceutical company, experienced a significant security breach initiated through an exposed GitHub personal access token found in client-side JavaScript on a subdomain. The threat group FulcrumSec exploited this token to clone private repositories, harvest additional credentials, and infiltrate deeper into the company's network. Over a span of more than two months, the attackers exfiltrated approximately 1.3TB of sensitive data, including source code, proprietary drug information, clinical trial data, internal AI models, and personal information of healthcare professionals and clinical trial participants. The breach was publicly disclosed on June 11, 2026, after unauthorized access to internal IT systems was detected. This incident highlights the critical vulnerabilities in software development pipelines, particularly concerning secrets management and the security of code repositories. The reliance on hardcoded credentials and improperly scoped access keys within development environments presents a substantial risk. Organizations are urged to treat development platforms as production systems, enforce stringent secrets management practices, and implement robust monitoring to prevent similar breaches.
3 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports