Ransomware victim disclosure
← All victimsHetero
listed as hetero.com · Claimed by Orion · listed 3 days ago
Status timeline
- ListedAug 5, 2026
- Data leakeddate unknown
At a glance
- Group
- Orion
- Status
- Data leaked
- Sector
- Healthcare
- Listed on leak site
- Aug 5, 2026
About the victim
AI dossier — public-source company profileHetero is a leading global pharmaceutical company headquartered in India with 30 years of experience in the industry. They specialize in anti-retroviral drugs, APIs, global generics, biosimilars, and custom pharmaceutical services, with manufacturing facilities and presence across multiple countries including Colombia, Dominican Republic, Guatemala, Indonesia, Kazakhstan, Philippines, South Africa, Vietnam, and Malaysia.
- Industry
- Pharmaceutical Manufacturing & APIs
- Founded
- 1993
Attack summary
Severity: medium — Confirmed data publication by ransomware operator against a pharmaceutical company handling sensitive manufacturing and drug data; however, the leak post itself is extremely sparse with no visible proof files, data inventory, or specific claims about exfiltration scope or type of data compromised.The ransomware group Orion claims to have compromised hetero.com. The leak post provides minimal detail on the attack scope, data exfiltrated, or operational disruption.
What the group claims
hetero.com
Sources
Source
Indexed 3 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

