Ransomware victim disclosure
← All victimsApteki Mareshki
Claimed by Thegentlemen · listed 20 hours ago
Status timeline
- ListedSep 15, 2026
- Data leakeddate unknown
At a glance
- Group
- Thegentlemen
- Status
- Data leaked
- Country
- Bulgaria
- Sector
- Healthcare
- Listed on leak site
- Sep 15, 2026
About the victim
AI dossier — public-source company profileApteki Mareshki is Bulgaria's largest pharmacy chain by outlet count, operating 294 pharmacies across 120+ towns. Founded in 1991–92 by Veselin Mareshki, the chain operates through dozens of legal entities under the MARESHKI HOLD AD umbrella due to Bulgarian regulatory caps on single-entity pharmacy ownership, and is supplied through the group's own wholesaler Farmnet AD.
- Industry
- Pharmacy & Drug Retail
- Address
- Bulgaria (multiple locations: 294 pharmacies across 120+ towns)
- Founded
- 1991
Attack summary
Severity: medium — Healthcare sector entity with national operational scale (294 outlets); however, no proof files, data inventory, or specific exfiltration claims are published in the disclosed post. Encryption-only claim or announcement without substantiation.TheGentlemen claims to have compromised Apteki Mareshki's systems. No specific data categories or operational impact are detailed in the leak post.
What the group claims
mareshki.com Apteki Mareshki Bulgaria's largest pharmacy chain by outlet count — 294 pharmacies in 120+ towns (2025), built since 1991–92 by Veselin Mareshki, the Varna businessman, founder of the Volya party and former deputy speaker of parliament. Because Bulgarian law caps one company at 4 pharmacies, the chain runs as dozens of legal entities (owned by his mother Veska, relatives and their children) under the MARESHKI HOLD AD umbrella, franchising the brand from Varnafarma-M and supplied through his own wholesaler Farmnet AD (bought from Actavis in 2010; 2016 revenue 494.8M leva, top-4 drug distributor — together with Sofarma Trading, Phoenix and Sting handling ~80% of national distribution)
Sources
- Victim sitemareshki.com
Source
Indexed 20 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

