Ransomware victim disclosure
← All victimsLabexpress
Claimed by INC Ransom · listed 18 hours ago
Status timeline
- Listed
May 31, 2026
- Data leaked
At a glance
- Group
- INC Ransom
- Status
- Data leaked
- Country
- US
- Sector
- Pharmaceutical
- Listed on leak site
- May 31, 2026
- Data size
- 200GB
- Records
- 20 files
What the group claims
US-based group operating under two legal entities: Labexpress and Garonit Pharma. Attackers obtained 200 GB of internal data including a single Active Directory domain (LABEXPRESS1.local), a shared file server, and extensive cross-company records. Data includes financial & accounting records, quality & production documents, ANDA & regulatory documentation, vendor & customer records, and HR information.
The leak post
captured from the group's site```
{"type":true,"message":"Success: got announcements.","payload":{"length":713,"announcements":[{"_id":"6a0a55f6d152110a6acc24fa","company":{"company_name":"Meirc%20training%20and%20consulting","country":"AE","revenue":21000000},"categories":["Encrypted","Proof"],"description":["Meirc%20offer%20a%20wide%20range%20of%20training%20programs%20across%20various%20categories%2C%20including%20accounting%2C%20finance%2C%20artificial%20intelligence%2C%20project%20management.%0D","They%20is%20recognized%20as%20a%20%22trusted%22%20training%20and%20consulting%20partner.%0D","%0D","We%20accessed%20the%20entire%20MEIRC%20network%20and%20downloaded%201TB%20of%20data%0D","-%20accounting%0D","-%20internal%20mail%0D","-planning%0D","-%20budgets%0D","-%20all%20personal%20information%20of%20all%20employees%20of%20the%20company%0D","%0D","In%20a%20week%20everything%20will%20be%20in%20the%20public%20domain."],"logo":"6a0a55f6d152110a6acc24e2","proof":["6a0a55f6d152110a6acc24cd","6a0a55f6d152110a6acc24ce","6a0a55f6d152110a6acc24cf","6a0a55f6d152110a6acc24d0","6a0a55f6d152110a6acc24d1","6a0a55f6d152110a6acc24d2","6a0a55f6d152110a6acc24d3","6a0a55f6d152110a6acc24d4","6a0a55f6d152110a6acc24d5","6a0a55f6d1…Data the group says was taken
- Active Directory dump
- financial records
- accounting records
- QuickBooks data
- invoices
- batch records
- ANDA regulatory documentation
- vendor records
- customer records
- HR records
- email/mailbox data
Screenshot of the leak post

Sources
Source
Indexed 18 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.
