Ransomware victim disclosure
← All victimsPonce & Benzo
listed as ponce-benzo.com · Claimed by Lockbit5 · listed 5 hours ago
Status timeline
- ListedJun 20, 2026
- Data leakeddate unknown
At a glance
- Group
- Lockbit5
- Status
- Data leaked
- Country
- Puerto Rico
- Listed on leak site
- Jun 20, 2026
About the victim
AI dossier — public-source company profilePonce & Benzo is a Puerto Rico-based manufacturer and marketer of pharmaceutical and consumer care products established in 1923. The company produces multiple branded product lines including Dencorub, Dioxogen, OverSkin, pHfem, Vitenol, Wampole, and Adel, serving regional markets with topical analgesics, antiseptic solutions, and personal care items.
- Industry
- Pharmaceutical & Consumer Healthcare Products
- Founded
- 1923
Attack summary
Severity: medium — Data has been published by the ransomware group and the company operates in a regulated pharmaceutical/healthcare sector, elevating concern. However, the leak post is truncated and provides no specifics on data sensitivity, volume, or whether customer/patient PII was exfiltrated. No proof files or screenshots are documented.LockBit5 claims to have compromised Ponce & Benzo and exfiltrated business data. The group post states they manufacture and market consumer goods products but provides no specific details of the attack scope or data categories extracted.
Data the group says was taken
AI dossier — extracted from the leak post- Business operational data
- Product development records
- Company infrastructure information
What the group claims
We are dedicated to the manufacture and marketing of our own and third-party products in the mass co...
Sources
Source
Indexed 5 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

