Ransomware victim disclosure
← All victimsAnthem Biosciences
listed as anthembio.com · Claimed by Warlock · listed 1 year ago
Status timeline
- ListedAug 17, 2025
- Data leakeddate unknown
At a glance
- Group
- Warlock
- Status
- Data leaked
- Country
- United States
- Sector
- Healthcare
- Listed on leak site
- Aug 17, 2025
About the victim
AI dossier — public-source company profileAnthem is a CRDMO (Contract Research, Development & Manufacturing Organization) providing integrated services across drug discovery, development, and commercial manufacturing for small molecules, peptides, lipids, oligonucleotides, high-potent APIs, and large molecule biologics. The company operates cGMP manufacturing facilities and serves pharmaceutical and biotech clients from early-stage discovery through commercial production.
- Industry
- Contract Research, Development & Manufacturing Organization (CRDMO) / Pharmaceutical & Biotech Services
Attack summary
Severity: high — A CRDMO's primary asset is confidential pharmaceutical R&D data and manufacturing processes for client drugs in development. Exfiltration of such data exposes trade secrets, regulatory filings, and potentially compromises multiple pharmaceutical clients' intellectual property and competitive advantage. Healthcare sector classification and 'all data' disclosure claim elevate severity despite lack of proof details.The group claims to have obtained 'all data' from Anthem Bio, with disclosed status indicating data has been published. No specific details on data categories, exfiltration method, or operational impact are provided in the leak post.
Data the group says was taken
AI dossier — extracted from the leak post- Drug discovery research data
- Manufacturing process documentation
- Client pharmaceutical compounds and formulations
- Regulatory submissions and CMC documentation
- Quality assurance and analytical test results
- Potentially confidential client data
What the group claims
all data
Sources
- Victim siteanthembio.com
Source
Indexed 1 year agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

