Ransomware victim disclosure
← All victimsCrystal Pharmatech
Claimed by Qilin · listed 2 days ago
Status timeline
- ListedAug 6, 2026
- Data leakeddate unknown
At a glance
- Group
- Qilin
- Status
- Data leaked
- Country
- United States
- Sector
- Healthcare
- Listed on leak site
- Aug 6, 2026
About the victim
AI dossier — public-source company profileCrystal Pharmatech is a global CDMO and CRO specializing in solid-state formulation, drug development, and manufacturing services. The company operates across small-molecule pharmaceuticals, biologics, and nucleic acid therapeutics, with facilities in Asia-Pacific and the United States, and provides services including API development, crystallization, formulation, analytical characterization, and GMP-compliant manufacturing.
- Industry
- Contract Development and Manufacturing Organization (CDMO) & Clinical Research Organization (CRO) — Pharmaceutical
Attack summary
Severity: high — Crystal Pharmatech is a pharmaceutical CDMO/CRO with access to proprietary drug formulations, manufacturing processes, clinical trial data, and client intellectual property. Exfiltration of such data poses significant risk to pharmaceutical clients, competitive harm, and potential exposure of clinical/regulatory information. The lack of detailed proof or ransom demand does not reduce the sensitivity of the sector and likely data types involved.The ransomware group Qilin claims to have published data from Crystal Pharmatech. No specific details about the attack method (encryption vs. exfiltration) or data categories are provided in the available post excerpt.
What the group claims
N/A
Sources
Source
Indexed 2 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

