Ransomware victim disclosure
← All victimsHanDok
Claimed by ULose · listed 2 months ago
Status timeline
- ListedJun 9, 2026
- Data leakeddate unknown
At a glance
- Group
- ULose
- Status
- Data leaked
- Country
- South Korea
- Sector
- Healthcare
- Listed on leak site
- Jun 9, 2026
About the victim
AI dossier — public-source company profileHanDok is a South Korean total healthcare company with a 70-year history. They develop and distribute prescription pharmaceuticals, over-the-counter medications, in vitro diagnostic devices, medical devices, and digital health solutions. The company operates R&D facilities and maintains a portfolio of consumer health brands.
- Industry
- Pharmaceuticals & Healthcare
- Address
- Seoul, Gangnam-gu, Teheran-ro 132 (ZIP 06235), South Korea
Attack summary
Severity: high — Confirmed exfiltration and public disclosure of customer data from a regulated pharmaceutical/healthcare company operating in South Korea. Healthcare customer records constitute sensitive personal information subject to regulatory protection (PIPA in South Korea).ULose claims to have exfiltrated all customer data from HanDok. The group has published the data and lists it as publicly available, though no specific data categories or volume are detailed in the leak post.
Data the group says was taken
AI dossier — extracted from the leak post- customer records
- customer personal information
What the group claims
We have all customer`s data of HanDok country: South Korea status: public
Sources
- Victim sitewww.handok.co.kr
Source
Indexed 2 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

