Ransomware victim disclosure
← All victimsidi pharma
Claimed by Deadlock · listed 5 hours ago
Status timeline
- ListedOct 9, 2026
- Data leakeddate unknown
At a glance
- Group
- Deadlock
- Status
- Data leaked
- Country
- Spain
- Sector
- Healthcare
- Listed on leak site
- Oct 9, 2026
About the victim
AI dossier — public-source company profileidi pharma is an Italian pharmaceutical company based in Aci Bonaccorsi (Sicily) specializing in research and development of innovative nutraceuticals and medical devices. The company focuses on patented formulations and proprietary dosage technologies targeting fertility, urology, gynecology, and sexual health, with a mission to improve patient quality of life through high-quality therapeutic solutions.
- Industry
- Pharmaceutical Research & Development – Nutraceuticals and Medical Devices
- Address
- Via Goffredo Mameli, 12, 95020 Aci Bonaccorsi CT, Italy
Attack summary
Severity: medium — Data has been published by the threat actor (disclosed_status = data_published), confirming exfiltration. However, no specific data types are detailed in the leak post, no proof files are advertised, and the healthcare sector classification alone (without confirmation of PII, patient records, or regulatory data) does not elevate to 'critical'. Medium reflects confirmed data publication without detailed evidence of sensitive regulated data.Deadlock claims to have exfiltrated data from idi pharma. The leak post does not specify the scope of data theft (encryption, exfiltration, or both) or itemize what confidential information was taken.
What the group claims
idi pharma is an Italian pharmaceutical company specializing in the research and development of innovative nutraceuticals and medical devices. The company focuses on formulations covered by patents and unique dosage technologies to improve patient health and quality of life (but their data leak).
Sources
- Victim sitewww.idipharma.com
Source
Indexed 5 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

