Ransomware victim disclosure
← All victimsNeoPharma Labs
listed as neopharmlabs.com · Claimed by Chaos · listed 7 days ago
Status timeline
- ListedJul 22, 2026
- Data leakeddate unknown
At a glance
- Group
- Chaos
- Status
- Data leaked
- Country
- United States
- Sector
- Healthcare
- Listed on leak site
- Jul 22, 2026
About the victim
AI dossier — public-source company profileNeoPharma Labs (neopharmlabs.com) is a pharmaceutical company operating in the United States. Limited public information is available about the organization's scale or specific operations.
- Industry
- Pharmaceutical Manufacturing & Research
Attack summary
Severity: critical — Healthcare sector with confirmed large-scale data exfiltration (627 GB) and partial publication. Pharmaceutical companies typically hold sensitive IP, clinical trial data, and PII; breach of this scale in healthcare is critical.The Chaos group claims to have exfiltrated 627 GB of data from NeoPharma Labs and has published a 3% sample (approximately 19 GB) as proof. The group is demanding ransom and threatening further disclosure if management does not engage within 48 hours.
Data the group says was taken
AI dossier — extracted from the leak post- business records
- proprietary pharmaceutical data
- operational files
The group's post references roughly 3% of 627 GB dataset published proof files.
What the group claims
Notice of Data Escalation: 3% Proof Publication Management is ignoring the seriousness of the situation and refusing to engage in dialogue. We are publishing a 3% sample of our 627 GB archive right now. We are giving management 48 hours to reach out to us. If they fail to contact us within this ti…
Sources
Source
Indexed 7 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

