On October 25, 2023, clinical research technology provider Advarra Inc. appeared on the leak site of the Alphv ransomware group. The listing states that internal files were exfiltrated during a ransomware attack. While the exact number of individuals affected remains unknown, the breach touches anyone whose clinical trial records, IRB documentation, or related personal information passed through Advarra’s systems, including participants connected to major sponsors such as Pfizer and Gilead.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Advarra Inc.(PFIZER,GILEAD ETC AFFECTED)
Get alerted the next time Advarra Inc.(PFIZER,GILEAD ETC AFFECTED) files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Advarra Inc.(PFIZER,GILEAD ETC AFFECTED)’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Details in the Leak-Site Listing
The Alphv leak page, still accessible via its onion address as of the initial publication, claims that Advarra’s internal files were stolen and will be published if a ransom is not paid. The disclosure does not quantify the volume or specific categories of data beyond stating that internal files were exfiltrated. It does not list individual record counts, nor does it name particular databases or applications compromised. The posting follows the group’s standard format: a victim profile, screenshots of allegedly stolen material, and a countdown timer. Public reporting on Alphv indicates the group often uses these listings to pressure victims after initial encryption and data theft have already occurred.
Why This Matters for You and Your Family
If you or a family member have taken part in a clinical trial, signed an informed-consent form, or had medical data reviewed by an institutional review board managed by Advarra, your information may now sit in an attacker’s archive. Clinical trial data frequently includes names, dates of birth, medical histories, test results, contact details, and sometimes Social Security numbers. Exposure of this material creates immediate risks of identity theft, insurance fraud, and targeted phishing campaigns that reference real health conditions. Even if you never directly interacted with Advarra, the interconnected nature of clinical research means data from partner sites, contract research organizations, or academic institutions could still link back to you.
Doxxing and Identity-Chain Implications
Ransomware operators like Alphv rarely stop at posting generic files. They often comb stolen material for spreadsheets that connect names to addresses, phone numbers, email accounts, and employer details. Once these links surface, opportunistic criminals can build full identity profiles. A single leaked trial-participant record can chain to your online usernames, family members’ accounts, and even children’s gaming profiles that reuse the same email or password. These chains accelerate doxxing: attackers publish personal dossiers on forums, sell them in underground markets, or use them to impersonate you to banks, insurers, or family members. The longer the data remains unmonitored, the more connections an adversary can map.