Ransomware victim disclosure
← All victimsMedical Pharmacies
Claimed by Snatch · listed 5 years ago
Status timeline
- ListedDec 10, 2021
- Data leakeddate unknown
At a glance
- Group
- Snatch
- Status
- Data leaked
- Country
- Canada
- Sector
- Engineering
- Listed on leak site
- Dec 10, 2021
About the victim
AI dossier — public-source company profileMedical Pharmacies is a Canadian healthcare company specializing in medication management, specialty pharmacy services, and the provision of medical supplies and equipment. The organization serves the Canadian healthcare industry with a workforce of over 1,500 staff members. It is described as a leader in its field, including maintaining current awareness of drug recalls.
- Industry
- Specialty Pharmacy & Medical Supply Services
- Employees
- 1500
Attack summary
Severity: critical — The victim operates in the Canadian healthcare sector handling medication management and specialty pharmacy services, meaning exfiltrated data almost certainly includes regulated health information (PHI/PII) at scale across a large staff and patient base. Data has been confirmed published by the threat actor.The Snatch ransomware group claims to have attacked Medical Pharmacies and has published data ('data_published' status), suggesting confirmed exfiltration of company data. The specific data types and volume have not been detailed in the truncated post.
Data the group says was taken
AI dossier — extracted from the leak post- Employee records
- Patient/customer medication data
- Medical supply and equipment records
- Drug recall and compliance documentation
- Healthcare operational data
What the group claims
Medical Pharmacies is the leader in medication management, specialty pharmacy services and providing medical supplies and equipment to the Canadian healthcare industry. Working in a field that provides such critical services, their staff of over 1500 members has to be up-to-date on the latest drug recalls,
Source
Indexed 5 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

