Ransomware victim disclosure
← All victimsAlkaloid AD
listed as alkaloid.com.mk · Claimed by apt73 · listed 6 hours ago
Status timeline
- Listed
May 21, 2026
- Data leaked
At a glance
- Group
- apt73
- Status
- Data leaked
- Country
- MK
- Sector
- Healthcare
- Listed on leak site
- May 21, 2026
About the victim
AI dossier — public-source company profileAlkaloid is a pharmaceutical and chemical manufacturing company founded in Skopje, North Macedonia in 1936. The company produces pharmaceuticals (OTC medicines, medical devices, food supplements), botanicals, cosmetics, and industrial chemicals, with a global presence across multiple countries in Europe and Central Asia.
- Industry
- Pharmaceuticals & Chemical Manufacturing
- Address
- Skopje, North Macedonia
- Founded
- 1936
Attack summary
Severity: high — Confirmed data exfiltration from a major pharmaceutical manufacturer with international operations and regulated products. Healthcare sector company with sensitive manufacturing, R&D, and potentially employee/customer data at risk.APT73 claims to have compromised Alkaloid and published exfiltrated data. The specific data categories and operational details of the breach are not fully detailed in the available post excerpt.
Data the group says was taken
AI dossier — extracted from the leak post- Corporate records
- Financial data
- Employee information
- Research & development data
- Manufacturing processes
What the group claims
Alkaloid is a pharmaceutical company from Northern Macedonia, founded in Skopje in 1936, producin...
The leak post
captured from the group's siteDeadline: 2026/05/25 12:00:00 UTC +0 Alkaloid is a pharmaceutical company from Northern Macedonia, founded in Skopje in 1936, producing medicines, cosmetics, chemical and herbal products for international markets. Internal documents, financial reports, sensitive information. Total size: 1 GB. | *Until the files will be available left* | *We always initially offer to buy data by origin company. But we are also ready to consider third-party offers.* | | --- | --- | *If you see that a timer is running in your company's block, you have a chance to avoid a data leak. To do this, you need to write to us in the form and indicate your details. Our support team will contact you shortly and help you. **You must understand that there is no time to think, you must make a decision quickly, the timer has started.** If you see a button at the bottom of your company's publication, this means that all data is publicly available. If you are a customer or employee of a company that has been affected, please contact us and give us the information about yourself that you want removed. We will check what we have related to you and remove it from the leak. **The price depends on the company s…
Sources
Source
Indexed 6 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
