Ransomware victim disclosure
← All victimsTriApex US Laboratories
Claimed by Nightspire · listed 5 months ago
Status timeline
- ListedJan 20, 2026
- Data leakeddate unknown
At a glance
- Group
- Nightspire
- Status
- Data leaked
- Country
- United States
- Listed on leak site
- Jan 20, 2026
About the victim
AI dossier — public-source company profileTriApex US Laboratories is the U.S. subsidiary of TriApex, a contract research organization (CRO) headquartered in China with laboratories launched in Philadelphia, Pennsylvania. The company provides nonclinical and clinical drug development services including safety assessment, toxicology, DMPK studies, bioanalysis, and clinical trial support across therapeutic areas such as ophthalmology, CNS, and metabolic disease. It serves pharmaceutical and biotech clients across the full drug development pipeline from IND-enabling studies through NDA/BLA submission.
- Industry
- Contract Research Organization (CRO) & Pharmaceutical Research Services
- Address
- Philadelphia, Pennsylvania, United States
Attack summary
Severity: critical — TriApex is a CRO handling regulated pharmaceutical research data including clinical trial records, drug safety assessments, and patient/subject-linked bioanalytical data. Data published by the threat actor likely includes sensitive regulated data (clinical trial PII, proprietary drug development data) subject to FDA, GCP, and HIPAA-adjacent regulations, making this a critical-severity disclosure.The Nightspire ransomware group claims an attack on TriApex US Laboratories and has published data (disclosed status: data_published), though the leak post contains no explicit description of encryption or exfiltration methods and no ransom amount or data volume was stated.
Data the group says was taken
AI dossier — extracted from the leak post- Clinical trial data
- Drug safety assessment records
- Nonclinical study data
- Pharmacokinetic/pharmacodynamic study data
- Bioanalysis results
- Regulatory submission documents
- Client/sponsor confidential research data
- Employee records
- Corporate governance documents
What the group claims
TriApex US Laboratories
Sources
- Victim sitetri-apex.com/info/news/headlines/596.html
Source
Indexed 5 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

