Ransomware victim disclosure
← All victimsApexus
listed as apexus.com · Claimed by Threeam · listed 6 hours ago
Status timeline
- ListedSep 28, 2026
- Data leakeddate unknown
At a glance
- Group
- Threeam
- Status
- Data leaked
- Country
- United States
- Sector
- Technology
- Listed on leak site
- Sep 28, 2026
About the victim
AI dossier — public-source company profileApexus is the HRSA-designated Prime Vendor for the 340B Drug Pricing Program, a federal initiative that allows eligible healthcare entities to obtain discounted medications. The company provides education, compliance support, refund services, and technical assistance to 340B stakeholders, and also offers professional certification programs and fellowship opportunities in health-system pharmacy.
- Industry
- Healthcare Services & Pharmaceutical Program Management
- Founded
- 2007
Attack summary
Severity: medium — Data has been published and the breach is confirmed (disclosed status: data_published), but no proof files, data inventory, or specific sensitive information types are detailed in the leak post. Apexus handles healthcare program administration and may hold PII/PHI related to 340B participants, but without confirmation of exfiltration scope or content, severity cannot be raised to high.The threeam group claims to have breached Apexus and published data. The leak post does not specify what data was exfiltrated, whether encryption occurred, or what categories of information are at risk.
What the group claims
Apexus, founded in 2007, is a business services company that manages the 340B Prime Vendor Program supporting the 340B Drug Pricing Program. The company negotiates pricing discounts with pharmaceutical manufacturers, provides educational resources
Sources
Source
Indexed 6 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

