Ransomware victim disclosure
← All victimsPharma5
listed as pharma5.ma · Claimed by Incransom · listed 4 hours ago
Status timeline
- ListedSep 25, 2026
- Data leakeddate unknown
At a glance
- Group
- Incransom
- Status
- Data leaked
- Country
- Morocco
- Sector
- Healthcare
- Listed on leak site
- Sep 25, 2026
About the victim
AI dossier — public-source company profilePharma5 is a pharmaceutical company based in Casablanca, Morocco, engaged in drug manufacturing, product supply, quality control, and certification. The company operates from a registered office address in the Maârif Extension district.
- Industry
- Pharmaceutical Manufacturing & Distribution
- Address
- 21, Rue des Asphodèles, Maârif Extension, 20100 Casablanca, Morocco
Attack summary
Severity: critical — Exfiltration of 50 GB including regulated pharmaceutical data (drug testing, certifications), employee PII, and sensitive financial/operational information from a healthcare/pharma entity constitutes critical exposure of regulated sensitive data.incransom claims to have exfiltrated approximately 50 GB of data from Pharma5, including corporate and financial records, product information, supply chain data, quality control and drug testing documentation, and employee personal information.
Data the group says was taken
AI dossier — extracted from the leak post- Corporate and financial records
- Product information and specifications
- Supply chain and supplier data
- Quality control documentation
- Drug testing and certification records
- Employee personal data
- Counterparty information
What the group claims
Pharma5 21, Rue des Asphodèles, Maârif Extension, 20100 Casablanca, Morocco 05 22 23 62 15 pharma5.ma Leaked data: 50Gb Corporate and financial information, data on products and their supply, quality control and certification, drug testing and related issues, employee personal data, counterparties, and much more.
Sources
Source
Indexed 4 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

