Skip to main content

Ransomware victim disclosure

All victims

Jilin Drug Administration (吉林省药品监督管理局)

listed as AG真人 (Jilin Drug Administration) · Claimed by Pryx · listed 2 hours ago

Today
Age
since listed · listed for ransom

Status timeline

  1. ListedAug 25, 2026

Current state: Listed for ransom

At a glance

Group
Pryx
Status
Listed for ransom
Country
China
Listed on leak site
Aug 25, 2026

About the victim

AI dossier — public-source company profile

The Jilin Drug Administration is a provincial government agency under China's market regulation authority, responsible for pharmaceutical and medical device oversight in Jilin Province. It manages drug licensing, pharmaceutical manufacturing permits, medical device registration, and pharmaceutical quality assurance across the region.

Industry
Government / Pharmaceutical Regulation
Address
Jilin Province, Changchun City, Economic and Technological Development Zone, Zhanjiang Road 657 (intersection of Xiantai Street and Zhanjiang Road)

Attack summary

Severity: low — The disclosed content consists of publicly available government regulatory announcements and notices. No confidential personal information, medical records, or sensitive government data has been identified. The materials appear to be routine administrative disclosures already published on the official website.

Pryx claims to have accessed and published content from the Jilin Drug Administration's website, including official notices, pharmaceutical licensing announcements, and regulatory documents. The leak appears to consist of publicly available government announcements rather than confidential data.

low

Data the group says was taken

AI dossier — extracted from the leak post
  • Official regulatory notices
  • Drug manufacturing permits
  • Medical device registration documents
  • Pharmaceutical licensing information
  • Quality assurance announcements

What the group claims

Jilin Province Drug Administration (吉林省药品监督管理局), a Chinese government regulatory body overseeing pharmaceutical and medical device registration, licensing, and standards in Jilin Province.

The leak post

captured from the group's site
* [AG真人关于印发《第二类医疗器械注册审批流程》的通知 吉药监械注册〔2026...](https://www.pryx.cc/zxfw_84842/tzwj/202603/t20260325_9456045.html "AG真人关于印发《第二类医疗器械注册审批流程》的通知     吉药监械注册〔2026〕10 号")


  * [AG真人 核发《药品生产许可证》公示 (2026年第5期)](https://www.pryx.cc/zxfw_84842/gsgg/ypscgsgg/202608/t20260818_9683346.html "AG真人  核发《药品生产许可证》公示  (2026年第5期)")
  * [AG真人关于发布11个吉林省中药配方颗粒标准(2026 年第二批) (试行)的公告](https://www.pryx.cc/zxfw_84842/gsgg/ypzcgsgg/202608/t20260818_9683350.html "AG真人关于发布11个吉林省中药配方颗粒标准(2026 年第二批)    (试行)的公告")
  * [AG真人 关于撤(注)销刘文静《执业药师注册证》的公告 (2026年第14期)](https://www.pryx.cc/zxfw_84842/gsgg/qtgsgg/202608/t20260811_9679913.html "AG真人 关于撤(注)销刘文静《执业药师注册证》的公告    (2026年第14期)")

Screenshot of the leak post

Leak screenshot for AG真人 (Jilin Drug Administration)

Sources

Source

Indexed 2 hours ago

This page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.

Is this your supplier? Your competitor? You?

Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

Disclosure context

About Pryx

Auto-discovered from ransomware tracking sources The group has been linked to 7 public disclosures across our corpus. First observed on a leak site on May 15, 2026; most recent post August 25, 2026. The operation is currently active.

Timeline of this disclosure

  • August 25, 2026AG真人 (Jilin Drug Administration) listed by Pryxon the group's public leak site

Sector and geography

This disclosure adds to ransomware activity in the Government / Pharmaceutical Regulation sector. Geographically, AG真人 (Jilin Drug Administration) is reported in China, a country with 72 ransomware disclosures in our corpus.

If your organisation is affected

A listing by Pryx means AG真人 (Jilin Drug Administration) appeared on a ransomware extortion site and is being pressured to pay before any publication. If this is your organisation, or a supplier you depend on, the priority is to confirm the intrusion and contain it before the window to act closes.

  • Engage your incident-response team and preserve forensic evidence before remediating — do not wipe affected systems first.
  • Force a password reset and revoke active sessions for exposed accounts; rotate any credentials, API keys or certificates that may have been in the stolen data.
  • Assess regulatory notification duties (GDPR, NIS2, sector regulators) — many carry a 72-hour reporting clock from awareness.
  • Monitor for the data appearing on Pryx's leak site and across paste and breach channels, and brief downstream partners who may be exposed through you.

How we know this. Darkfield monitors public ransomware leak sites continuously, archiving every new disclosure and the data later released against the victim. Each entry on this page is sourced from the operator's own publication and cross-checked against complementary OSINT feeds (RansomLook, ransomware.live, RansomWatch). We do not collect or host stolen data — only the metadata, timestamps and screenshots needed to make the public disclosure searchable and accountable. Records here are corrected when the original post is edited, retracted, or merged with another disclosure.