Ransomware victim disclosure
← All victimsKewaunee Scientific Corporation
listed as Kewaunee Scientific · Claimed by Incransom · listed 2 days ago
Status timeline
- ListedJun 11, 2026
- Data leakeddate unknown
At a glance
- Group
- Incransom
- Status
- Data leaked
- Country
- United States
- Sector
- Manufacturing
- Listed on leak site
- Jun 11, 2026
About the victim
AI dossier — public-source company profileKewaunee Scientific is a manufacturer of laboratory equipment and furniture serving research institutions, pharmaceutical companies, and industrial clients. The company supplies major clients including pharmaceutical firms and global laboratories.
- Industry
- Laboratory Equipment & Furniture Manufacturing
Attack summary
Severity: high — Confirmed exfiltration of 504 GB including financial records, client contracts with regulated pharmaceutical entities (Pfizer, Samsung), technical IP, and personal data. High-profile client exposure and scale of sensitive business data constitute significant risk.The incransom group claims to have exfiltrated 504 GB of data across 852,141 files, including confidential client information, financial records, contracts, and technical drawings. The group has threatened to publish full data within weeks.
Data the group says was taken
AI dossier — extracted from the leak post- Client contracts and Know Your Customer (KYC) documents
- Non-Disclosure Agreements (NDAs)
- Financial documentation
- Technical drawings and specifications
- Audit reports
- Personal data (employees/contractors)
- Contractor and subcontractor information
- Scanned confidential documents
What the group claims
Total data: 504GB Contains: 852,141 Files, 120,670 Folders Documents: Clients KYS & NDA, Financial documentation, Contracts, Drawings, Audit reports, Personal data, Contractors and subcontractors information, Scanned documents and much other important information. Tape: confidential Clients: Pfizer, Rusan Pharma Ltd., Samsung and many other world-famous laboratories. full information will be released in a few weeks
Sources
Source
Indexed 2 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

