Ransomware victim disclosure
← All victimsKhandelwal Laboratories Pvt Ltd
listed as Khandelwal Laboratories Pvt · Claimed by Hunters · listed 2 years ago
Status timeline
- ListedAug 2, 2024
- Data leakeddate unknown
At a glance
- Group
- Hunters
- Status
- Data leaked
- Country
- India
- Sector
- Healthcare
- Listed on leak site
- Aug 2, 2024
About the victim
AI dossier — public-source company profileKhandelwal Laboratories is a privately owned Indian pharmaceutical company founded in 1945 with headquarters in Mumbai. It specializes in research, development, manufacturing, and distribution of patented pharmaceutical formulations, NDDS (novel drug delivery systems), and niche APIs, with particular strength in oncology, antibiotics, and pain management. The company supplies over 250,000 doctors and 100,000 pharmacies across India and maintains 222+ patents.
- Industry
- Pharmaceutical Manufacturing & APIs
- Address
- Mumbai, India (headquarters); factories in Thane, Dadra, and Rudrapur
- Employees
- 1000+
- Founded
- 1945
Attack summary
Severity: high — Healthcare sector with confirmed dual-vector attack (encryption + exfiltration). Pharmaceutical company with 1000+ employees, proprietary formulations, 222+ patents, and sensitive manufacturing IP represents significant business and potentially patient safety impact. Data exfiltration of pharmaceutical R&D and manufacturing data poses competitive and regulatory risk.The hunters group claims to have both encrypted Khandelwal Laboratories' systems and exfiltrated data from the company. The specific nature and scope of exfiltrated data is not detailed in the available post excerpt.
Data the group says was taken
AI dossier — extracted from the leak post- Pharmaceutical formulations & R&D data
- API specifications
- Patent documentation
- Manufacturing processes & quality data
- Customer & distribution records
- Business operations data
What the group claims
Country : India - Exfiltraded data : yes - Encrypted data : yes
Sources
Source
Indexed 2 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

