Ransomware victim disclosure
← All victimsMedipak Limited
listed as medipakpharma.com · Claimed by Dragonforce · listed 4 days ago
Status timeline
- ListedJun 29, 2026
- Data leakeddate unknown
At a glance
- Group
- Dragonforce
- Status
- Data leaked
- Country
- Pakistan
- Sector
- Healthcare
- Listed on leak site
- Jun 29, 2026
About the victim
AI dossier — public-source company profileMedipak Limited is a Pakistani pharmaceutical manufacturer established in 1982 as the first integrated infusion solution and IV administration set manufacturing facility in Pakistan, with technical collaboration from Fresenius AG (Germany). The company produces large-volume parenterals, dialysis and irrigation solutions, IV administration sets, medical devices, ophthalmic preparations, and solid dosage pharmaceuticals for domestic and export markets.
- Industry
- Pharmaceutical Manufacturing & Medical Devices
- Address
- 132/1, Quaid-e-Azam Industrial Estate, Kotlakhpat, Lahore 54700, Pakistan
- Founded
- 1982
Attack summary
Severity: medium — Data has been published by the group (disclosed_status: data_published), indicating confirmed exfiltration; however, no specific proof files, screenshots, or data inventory details are provided in the truncated leak post, and the data types at risk remain unspecified. The target is a pharmaceutical manufacturer handling medical products and potential patient/operational records, which raises concern but lacks granular evidence of regulated PII at scale.The dragonforce group claims to have breached Medipak Limited and published data. The post does not explicitly detail whether encryption, exfiltration, or both occurred, nor does it specify the data categories compromised.
What the group claims
The Pakistani pharmaceutical company Medipak Limited (***.com) specializes in the manufacture of infusion solutions, medical devices, and pharmaceutical products.
Sources
Source
Indexed 4 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

