Ransomware victim disclosure
← All victimsFarmacias Vilela
Claimed by Qilin · listed 5 months ago
Status timeline
- ListedJan 22, 2026
- Data leakeddate unknown
At a glance
- Group
- Qilin
- Status
- Data leaked
- Country
- Spain
- Sector
- Healthcare
- Listed on leak site
- Jan 22, 2026
About the victim
AI dossier — public-source company profileFarmacias Vilela is an Argentine retail pharmacy chain operating multiple branches (sucursales) in the Buenos Aires Metropolitan Area (AMBA). The company sells pharmaceutical products, dermocosmetics, fragrances, personal care, and baby products, and offers free delivery on orders above ARS 100,000 within AMBA. It operates an e-commerce platform at farmaciasvilela.com.ar.
- Industry
- Retail Pharmacy & Dermcosmetics
- Address
- Buenos Aires Metropolitan Area (AMBA), Argentina
Attack summary
Severity: high — The victim is a pharmacy chain operating in the healthcare sector, where customer data likely includes sensitive health/pharmaceutical information and PII. The status is 'data_published', indicating confirmed exfiltration and public release of data, elevating severity to high even without a stated data volume.The Qilin ransomware group has listed Farmacias Vilela under a disclosed/data-published status, implying exfiltration and/or publication of company data. No ransom amount or specific data volume has been stated in the post.
Data the group says was taken
AI dossier — extracted from the leak post- Customer personal data
- Prescription or pharmaceutical records
- Employee records
- Business/operational files
What the group claims
N/A
The leak post
captured from the group's siteLaw Firms & Legal Services [John G Yphantides A Professional Law](http://ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion/site/blog?uuid=1e464ce5-6e74-4e62-be0b-eac503e43af8) Law Firms & Legal Services Law Firms & Legal Services [Keller Williams Real Estate - Exton](http://ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion/site/blog?uuid=ac8e3226-6965-4f8e-a2d5-53a0dbce8535)
Sources
Source
Indexed 5 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

