Ransomware victim disclosure
← All victimsLabexpress
Claimed by Incransom · listed 3 months ago
Status timeline
- ListedMay 31, 2026
- Data leakeddate unknown
At a glance
- Group
- Incransom
- Status
- Data leaked
- Country
- United States
- Sector
- Pharmaceutical
- Listed on leak site
- May 31, 2026
- Data size
- 200GB
- Records
- 20 files
About the victim
AI dossier — public-source company profileLabexpress is a US-based pharmaceutical company operating under a shared infrastructure with Garonit Pharma. The organization maintains an Active Directory domain (LABEXPRESS1.local) with 65 computers, 142 user accounts, and operates mail servers running Exchange 2007. The company handles financial records, quality documentation, and batch records for pharmaceutical products.
- Industry
- Pharmaceutical Manufacturing & Distribution
- Employees
- 65-142
Attack summary
Severity: critical — Exfiltration of 200 GB from regulated pharmaceutical manufacturer including financial data, batch records, employee PII, and administrative credentials. Pharmaceutical sector is regulated (FDA, GMP); batch records and COA/COC documents are highly sensitive. Cross-company shared infrastructure compounds impact. Proof files published.INC Ransom claims to have exfiltrated 200 GB of internal data from Labexpress and its sister entity Garonit Pharma, including Active Directory dumps, financial records, employee information, QuickBooks data, and pharmaceutical batch records. The group has published proof files and states data will be made publicly available.
Data the group says was taken
AI dossier — extracted from the leak post- Active Directory domain data (65 computers, 142 user accounts, 98 groups)
- Financial records (QuickBooks Enterprise 2021, invoices, accounts payable)
- Employee personal information (142 user accounts)
- Email archives (Exchange 2007 mailbox exports)
- Pharmaceutical batch records (2023–2026)
- Quality assurance documents (COA/COC files)
- Client invoices and transaction records
- Administrator credentials and passwords
The group's post references roughly 21 proof files.
What the group claims
US-based group operating under two legal entities: Labexpress and Garonit Pharma. Attackers obtained 200 GB of internal data including a single Active Directory domain (LABEXPRESS1.local), a shared file server, and extensive cross-company records. Data includes financial & accounting records, quality & production documents, ANDA & regulatory documentation, vendor & customer records, and HR information.
The leak post
captured from the group's site```
{"type":true,"message":"Success: got announcements.","payload":{"length":713,"announcements":[{"_id":"6a0a55f6d152110a6acc24fa","company":{"company_name":"Meirc%20training%20and%20consulting","country":"AE","revenue":21000000},"categories":["Encrypted","Proof"],"description":["Meirc%20offer%20a%20wide%20range%20of%20training%20programs%20across%20various%20categories%2C%20including%20accounting%2C%20finance%2C%20artificial%20intelligence%2C%20project%20management.%0D","They%20is%20recognized%20as%20a%20%22trusted%22%20training%20and%20consulting%20partner.%0D","%0D","We%20accessed%20the%20entire%20MEIRC%20network%20and%20downloaded%201TB%20of%20data%0D","-%20accounting%0D","-%20internal%20mail%0D","-planning%0D","-%20budgets%0D","-%20all%20personal%20information%20of%20all%20employees%20of%20the%20company%0D","%0D","In%20a%20week%20everything%20will%20be%20in%20the%20public%20domain."],"logo":"6a0a55f6d152110a6acc24e2","proof":["6a0a55f6d152110a6acc24cd","6a0a55f6d152110a6acc24ce","6a0a55f6d152110a6acc24cf","6a0a55f6d152110a6acc24d0","6a0a55f6d152110a6acc24d1","6a0a55f6d152110a6acc24d2","6a0a55f6d152110a6acc24d3","6a0a55f6d152110a6acc24d4","6a0a55f6d152110a6acc24d5","6a0a55f6d1…Data the group says was taken
- Active Directory dump
- financial records
- accounting records
- QuickBooks data
- invoices
- batch records
- ANDA regulatory documentation
- vendor records
- customer records
- HR records
- email/mailbox data
Screenshot of the leak post

Sources
Source
Indexed 3 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

